Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
n/a polkit — Red Hat Polkit
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .9492 99.9 YES
AFFECTED
Product Versions Fixed
polkit all – —
TIMELINE
Nov 29 Reserved by redhat
Jun 27 Added to CISA KEV, remediation due 2022-07-18
Jun 27 Published (CNA: redhat)
Aug 15 EXPLOIT PUBLISHED — CVE-2021-4034 (polkit). Public exploit reference added.
Description
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| November 29, 2021 | Reserved | Reserved by redhat |
| June 27, 2022 | KEV ADDED | Added to CISA KEV, remediation due 2022-07-18 |
| June 27, 2022 | Published | Published (CNA: redhat) |
| August 15, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2021-4034 (polkit). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| n/a | polkit | — | all | — |
References (13)
- http://packetstormsecurity.com/files/166196/Polkit-pkexec-Local-Privilege-Escalation.html [Exploit, Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/166200/Polkit-pkexec-Privilege-Escalation.html [Third Party Advisory, VDB Entry]
- https://access.redhat.com/security/vulnerabilities/RHSB-2022-001 [Mitigation, Vendor Advisory]
- https://bugzilla.redhat.com/show_bug.cgi?id=2025869 [Issue Tracking, Patch]
- https://cert-portal.siemens.com/productcert/pdf/ssa-330556.pdf [Third Party Advisory]
- https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683 [Patch]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-4034 [US Government Resource]
- https://www.oracle.com/security-alerts/cpuapr2022.html [Patch, Third Party Advisory]
- https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt [Exploit, Mitigation, Third Party Advisory]
- https://www.secpod.com/blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034/ [Exploit, Third Party Advisory]
- https://www.starwindsoftware.com/security/sw-20220818-0001/ [Third Party Advisory]
- https://www.suse.com/support/kb/doc/?id=000020564 [Third Party Advisory]
- https://www.vicarius.io/vsociety/posts/pwnkit-pkexec-lpe-cve-2021-4034 [Exploit, Third Party Advisory]
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-4034 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.