Description
When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones.

- versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file
- versions older than v258 are not affected
- unrelated to the systemd service manager (pid 1 or user session managers)
- systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container)
- terminal-only or remote sessions (e.g.: ssh) are not affected
Published: 2026-08-10
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unprivileged user with a running desktop graphical session on a system where systemd-machined is at least version 259 (or 258 with a custom polkit rule granting the register‑machine action) can use the systemd API to terminate any process, including those owned by privileged users. The vulnerability is an access‑control bypass (CWE-284) that removes the boundary preventing ordinary users from sending kill signals to privileged processes. This can result in loss of service or unwanted process termination, potentially compromising system availability if key services are stopped.

Affected Systems

The flaw affects systemd-machined 259 and newer, and version 258 only when a local polkit policy grants unprivileged users the register‑machine action. Versions older than 258 are not affected. The issue occurs only on desktop systems where systemd-machined is installed, which is typically an optional separate package such as systemd‑container; it is not installed by default and is not part of the core systemd service manager. Terminal‑only or remote sessions such as SSH do not trigger the vulnerability.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate risk. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local desktop session; the attacker must be logged in to a user’s graphical environment with systemd-machined running. Exploitation requires only the ability to issue kill requests via the systemd interface, with no need for elevated privileges. Based on the description, it is inferred that terminating privileged processes may lead to denial of service or disruption of critical applications, but there is no explicit evidence of privilege escalation. The overall exploitability is low to moderate due to the local nature of the attack and the requirement for the user to be in a graphical session.

Generated by OpenCVE AI on August 10, 2026 at 18:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade systemd to version 259 or later (or apply any vendor‑provided patch that fixes the issue).
  • Remove or restrict any local polkit policy that grants the "register‑machine" action to unprivileged users.
  • If systemd-machined is not required for your environment, uninstall or disable the optional systemd‑container package.

Generated by OpenCVE AI on August 10, 2026 at 18:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8626-1 systemd vulnerabilities
History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Systemd
Systemd systemd-machined
Vendors & Products Systemd
Systemd systemd-machined

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file - versions older than v258 are not affected - unrelated to the systemd service manager (pid 1 or user session managers) - systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container) - terminal-only or remote sessions (e.g.: ssh) are not affected
Title systemd-machined: unprivileged users can terminate arbitrary processes
Weaknesses CWE-284
CWE-862
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Systemd Systemd-machined
cve-icon MITRE

Status: PUBLISHED

Assigner: systemd

Published:

Updated: 2026-08-10T17:57:14.676Z

Reserved: 2026-07-08T14:15:06.476Z

Link: CVE-2026-15060

cve-icon Vulnrichment

Updated: 2026-08-10T17:57:09.979Z

cve-icon NVD

Status : Received

Published: 2026-08-10T14:17:21.130

Modified: 2026-08-10T18:17:41.087

Link: CVE-2026-15060

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:22:50Z

Weaknesses