← Back to browse · API

CVE-2021-3560

Severity
HIGH
CVSS
7.8
EPSS
0.22193
Risk score
63.97
CISA KEV
Yes
PoC
Yes
Published
2022-02-16
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2021-26871, GHSA-7C49-J253-WQ5R
Products
Red Hat:Polkit, n/a:Polkit polkit 0.119, unix
Sources
cisa.gov CVE-2021-3560
packetstorm bd2236092be59388bfdefee2|CVE-2021-3560
euvd EUVD-2021-26871

Description

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

References