Skip to main content
EPSS 0.1%top 99%

CVE-2026-15060: CWE-284 in systemd systemd-machined

0
Medium
Published: 08/10/2026 (08/10/2026, 13:03:06 UTC)
Source: CVE Database V5
Vendor/Project: systemd
Product: systemd-machined

Description

When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file - versions older than v258 are not affected - unrelated to the systemd service manager (pid 1 or user session managers) - systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container) - terminal-only or remote sessions (e.g.: ssh) are not affected

CVSS v3.1

Score 4.7medium

Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected software

systemd

systemd-machined

Affected versions
=259
GitHub Actionsmore threats →cve
systemd-machined
pkg:github/systemd-machined
Affected versions
=259

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 19:32:43 UTC

Technical Analysis

The vulnerability CVE-2026-15060 in systemd-machined (version 259) arises when an unprivileged user in a desktop graphical session can kill arbitrary processes, including privileged ones. This occurs if systemd-machined version 259 is running or version 258 with a custom polkit policy granting register-machine access. The flaw is unrelated to the systemd service manager and does not affect terminal-only or remote sessions. systemd-machined is usually an optional package, such as systemd-container. Versions older than 259 are unaffected unless a local custom polkit policy grants unprivileged access to the register-machine action.

Potential Impact

An unprivileged user logged into a desktop graphical session can terminate arbitrary processes, including those running with elevated privileges, potentially disrupting system operations or services. This impact is limited to desktop graphical sessions where systemd-machined version 259 (or version 258 with a permissive polkit policy) is installed and running. Terminal-only or remote sessions are not affected.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid granting unprivileged access to the register-machine polkit action via custom policies. Additionally, consider not installing or running systemd-machined on desktop systems where this is not required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
systemd
Date Reserved
2026-07-08T14:15:06.476Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a79d51fbf8831d539c5a89a

Added to database: 08/10/2026, 13:41:51 UTC

Last enriched: 08/10/2026, 19:32:43 UTC

Last updated: 09/24/2026, 13:47:42 UTC

Views: 79

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses