Sceawere

Vulnerability Detail

CVE-2026-15060UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

systemd-machined Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
3h ago
Vendor
systemd
Product
systemd-machined
Attack Type
CWE-284
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
HIGH

Narrative and Response

Description

When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file - versions older than v258 are not affected - unrelated to the systemd service manager (pid 1 or user session managers) - systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container) - terminal-only or remote sessions (e.g.: ssh) are not affected

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-08-10T14:17:21.130Z",
  "pubdate": "2026-08-10T14:17:21.130Z",
  "executiveSummary": "An arbitrary process termination vulnerability exists within the systemd-machined component. The flaw allows an unprivileged local user logged into a desktop graphical session to terminate arbitrary processes, including privileged system processes.\nThis vulnerability impacts systems running systemd-machined version v259 or newer, or version v258 configured with a custom polkit policy that grants register-machine access to unprivileged users. Versions older than v258 are unaffected unless explicitly exposed via custom local polkit configurations.\nThe risk implication is severe, as local attackers can disrupt critical system services or applications, leading to potential denial of service conditions. Exploitation requires the attacker to have an interactive desktop graphical session on a system where systemd-machined is installed and active.\nTerminal-only and remote sessions, such as SSH, are not affected by this vulnerability. Furthermore, systemd-machined is typically distributed in an optional separate package, such as systemd-container, and is not commonly installed by default on standard desktop configurations.",
  "technicalDetails": "The vulnerability resides in the systemd-machined service, specifically affecting how machine registration and process management privileges interact with local desktop sessions through polkit authorization checks.\nIn systemd-machined version v259 and v258 (when a custom polkit policy permits register-machine access), the component fails to adequately restrict authorization boundaries for actions initiated by unprivileged users operating within a local desktop graphical session.\nThe attack flow begins when an unprivileged user authenticates locally and establishes a graphical desktop session. Leveraging the overly permissive access control or misconfigured polkit policy regarding the register-machine action, the attacker interacts with the systemd-machined D-Bus interface.\nThrough this interface, the attacker sends specially crafted requests to manipulate or terminate container environments or associated processes. Due to insufficient validation and privilege separation within the affected component, the operation improperly permits the termination of arbitrary target processes regardless of their elevated privilege level.\nAuthentication requirements are minimal, as the attacker only requires a local, interactive desktop graphical session. No prior administrative privileges are needed if the default v259 behavior or the v258 custom polkit policy condition is met.\nThe vulnerability is strictly local; network exposure and remote vectors such as SSH or terminal-only sessions are entirely unaffected. The issue is also independent of the core systemd service manager, isolating the vulnerable attack surface specifically to the systemd-machined daemon provided in packages like systemd-container."
}
CVE-2026-15060: systemd-machined Privilege Escalation Vulnerability (MEDIUM Severity, CVSS: 4.7) - Sceawere