A local account on a system with PackageKit enabled can become root without a password. The standard response is to treat this as a package-manager bug, but the real issue is that a central daemon trusted for routine software changes can hand out full administrative control to any local user.
CVE-2026-41651, called Pack2TheRoot, affects PackageKit versions 1.0.2 through 1.3.4 and is fixed in 1.3.5. The report says the flaw has existed for almost 12 years and was confirmed on Ubuntu Desktop and Server, Debian Desktop Trixie 13.4, RockyLinux Desktop 10.1, and Fedora 43 Desktop and Server.
The forward risk is persistence. If a local user can reach root through a package-management daemon, patching closes the bug but does not undo any access already gained, and the same trust model may exist across other distributions that ship PackageKit by default.