CVE-2026-15060: CWE-284 in systemd systemd-machined
When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file - versions older than v258 are not affected - unrelated to the systemd service manager (pid 1 or user session managers) - systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container) - terminal-only or remote sessions (e.g.: ssh) are not affected
AI Analysis
Technical Summary
The vulnerability CVE-2026-15060 in systemd-machined (version 259) arises when an unprivileged user in a desktop graphical session can kill arbitrary processes, including privileged ones. This occurs if systemd-machined version 259 is running or version 258 with a custom polkit policy granting register-machine access. The flaw is unrelated to the systemd service manager and does not affect terminal-only or remote sessions. systemd-machined is usually an optional package, such as systemd-container. Versions older than 259 are unaffected unless a local custom polkit policy grants unprivileged access to the register-machine action.
Potential Impact
An unprivileged user logged into a desktop graphical session can terminate arbitrary processes, including those running with elevated privileges, potentially disrupting system operations or services. This impact is limited to desktop graphical sessions where systemd-machined version 259 (or version 258 with a permissive polkit policy) is installed and running. Terminal-only or remote sessions are not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid granting unprivileged access to the register-machine polkit action via custom policies. Additionally, consider not installing or running systemd-machined on desktop systems where this is not required.
CVE-2026-15060: CWE-284 in systemd systemd-machined
Description
When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file - versions older than v258 are not affected - unrelated to the systemd service manager (pid 1 or user session managers) - systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container) - terminal-only or remote sessions (e.g.: ssh) are not affected
CVSS v3.1
Score 4.7medium
Affected software
systemd
systemd-machined
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-15060 in systemd-machined (version 259) arises when an unprivileged user in a desktop graphical session can kill arbitrary processes, including privileged ones. This occurs if systemd-machined version 259 is running or version 258 with a custom polkit policy granting register-machine access. The flaw is unrelated to the systemd service manager and does not affect terminal-only or remote sessions. systemd-machined is usually an optional package, such as systemd-container. Versions older than 259 are unaffected unless a local custom polkit policy grants unprivileged access to the register-machine action.
Potential Impact
An unprivileged user logged into a desktop graphical session can terminate arbitrary processes, including those running with elevated privileges, potentially disrupting system operations or services. This impact is limited to desktop graphical sessions where systemd-machined version 259 (or version 258 with a permissive polkit policy) is installed and running. Terminal-only or remote sessions are not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid granting unprivileged access to the register-machine polkit action via custom policies. Additionally, consider not installing or running systemd-machined on desktop systems where this is not required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- systemd
- Date Reserved
- 2026-07-08T14:15:06.476Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a79d51fbf8831d539c5a89a
Added to database: 08/10/2026, 13:41:51 UTC
Last enriched: 08/10/2026, 19:32:43 UTC
Last updated: 09/24/2026, 13:47:42 UTC
Views: 79
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.