CVE-2026-4105
Received
Received - Intake
Improper Access Control in systemd-machined Enables Root Execution
Publication date: 2026-03-13
Last updated on: 2026-04-30
Assigner: Red Hat, Inc.
Description
Description
A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| systemd | systemd | From 259 (inc) |
| systemd | systemd | From 259.4 (inc) |
| systemd | systemd | to 260 (inc) |
| systemd | systemd | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |