boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2021-4034HIGH
n/a polkit — Red Hat Polkit
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .9492   99.9   YES
AFFECTED
  Product  Versions  Fixed
  polkit   all –     —
TIMELINE
  Nov 29  Reserved by redhat
  Jun 27  Added to CISA KEV, remediation due 2022-07-18
  Jun 27  Published (CNA: redhat)
  Aug 15  EXPLOIT PUBLISHED — CVE-2021-4034 (polkit). Public exploit reference added.
CWE-125, CWE-787 · CNA: redhat · CVSS v3.1 · 13 references · NVD status: Analyzed · KEV due July 18, 2022

Description

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
November 29, 2021ReservedReserved by redhat
June 27, 2022KEV ADDEDAdded to CISA KEV, remediation due 2022-07-18
June 27, 2022PublishedPublished (CNA: redhat)
August 15, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2021-4034 (polkit). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
n/apolkitall

Weaknesses

CWE-125 · CWE-787

References (13)

Related

Authoritative record: CVE-2021-4034 at cve.org

Weaknesses: CWE-125 · CWE-787

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-4034 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.