PT-2026-69839 · Unknown · Systemd-Machined

CVE-2026-15060

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions systemd-machined versions 258 through 259 and later
Description When running on a desktop system, an unprivileged user logged into a desktop graphical session can terminate arbitrary processes, including those with higher privileges. This issue occurs in versions 259 and later, or in version 258 if a custom polkit policy is configured to allow unprivileged access to the register-machine action. This does not affect terminal-only or remote sessions, such as those established via ssh, and is unrelated to the systemd service manager.
Recommendations For version 258, restrict unprivileged access to the register-machine polkit action via the local policy configuration file. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15060
USN-8626-1

Affected Products

Systemd-Machined