Skip to main content

Impact of vulnerability CVE-2026-41651 on our products

A security vulnerability in “PackageKit” (CVE-2026-41651) has been identified. We would like to take this opportunity to inform you about the vulnerability and its implications.

I. Summary of the security vulnerability

PackageKit is a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. For more information, please visit https://nvd.nist.gov/vuln/detail/CVE-2026-41651.

II. Impact on our products

No products from TA Triumph-Adler and UTAX are affected by this vulnerability.