CVE-2026-78422 | z-galaxy zbus_polkit up to 5.0.x Subject::new_for_owner toctou

SecurityVulns

A vulnerability was found in z-galaxy zbus_polkit up to 5.0.x. It has been rated as very critical. Affected is the function Subject::new_for_owner. Performing a manipulation results in time-of-check time-of-use.

This vulnerability is identified as CVE-2026-78422. The attack is only possible with local access. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More