polkit vulnerabilities
CVEs whose affected-version data names the polkit package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-4897Medium· 5.5A flaw was found in polkit
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory…
▾ Sunlitfreedesktop · polkitEPSS 0.15%via NVD
CVE-2021-4034High· 7.8CISA KEVPoCA local privilege escalation vulnerability was found on polkit's pkexec utility
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current …
▾ Abyssalpolkit_project · polkitEPSS 95%via NVD