CVE-2021-3560
Red Hat Polkit Incorrect Authorization Vulnerability
- Published
- Feb 16, 2022
- Updated
- Oct 21, 2025
- Assigning CNA
- redhat
- Evidence observed
- Jun 15, 2021
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 97.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Sources
35- CVE-2021-3560Exploit
Polkit D-Bus Authentication Bypass Exploit
- polkit-auto-exploitExploit
Automatic Explotation PoC for Polkit CVE-2021-3560
- Polkit-exploitExploit
Privilege escalation with polkit - CVE-2021-3560
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.