CVE Tools

Polkit

15 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Polkit, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Polkit CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Polkit CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-071
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 15 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High533%
  • Medium960%
  • Low17%

Latest CVEs

The 15 most recently published vulnerabilities affecting Polkit.

  1. CVE-2026-4897Polkit: polkit: denial of service via unbounded input processing through standard input5.5
  2. CVE-2025-7519Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write6.7
  3. CVE-2021-4115There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NO...5.5
  4. CVE-2021-3560It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivil...7.8
  5. CVE-2021-4034A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users acc...7.8
  6. BDU:2021-05044Уязвимость службы polkit, позволяющая нарушителю создать учётную запись и повысить ее привилегии до уровня администратора6.2
  7. CVE-2019-6133In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to ...6.7
  8. CVE-2018-19788A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.8.8
  9. CVE-2018-1116A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger...4.4
  10. CVE-2016-2568pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.7.8
  11. CVE-2015-4625Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which trigge...4.6
  12. CVE-2015-3256PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (memory corruption and polkitd daemon crash) and possibly gain privileges via unspecified vectors, related to "ja...4.6
  13. CVE-2015-3255The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via duplicate action IDs in...4.6
  14. CVE-2015-3218The authentication_agent_new function in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (NULL pointer deref...2.1
  15. CVE-2013-4288Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is pe...7.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store