Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.1%top 99%

CVE-2026-16743: Improper Privilege Management in Red Hat Red Hat Enterprise Linux 10

0
Medium
VulnerabilityCVE-2026-16743cvecve-2026-16743
Published: 07/24/2026 (07/24/2026, 12:56:34 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Enterprise Linux 10

Description

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.

CVSS v3.1

Score 5.5medium

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/08/2026, 14:37:03 UTC

Technical Analysis

CVE-2026-16743 describes an improper privilege management flaw in accountsservice where the systemd-homed code path for SetIconFile opens a user-supplied filename as root without proper validation and privilege dropping. This allows a local attacker with a systemd-homed-managed account to read arbitrary files accessible to the accounts-daemon process. Red Hat's analysis confirms that their Red Hat Enterprise Linux 10 product is not affected because it does not include the vulnerable systemd-homed SetIconFile code path introduced in later upstream releases.

Potential Impact

The vulnerability could allow a local attacker to read arbitrary files accessible to the accounts-daemon process, resulting in a confidentiality breach. Integrity and availability are not impacted. Since Red Hat Enterprise Linux 10 is not affected, there is no impact on this product from this vulnerability.

Mitigation Recommendations

Red Hat states that Red Hat Enterprise Linux is not affected. For systems running vulnerable accountsservice builds, the mitigation is to avoid using systemd-homed-managed accounts. No official patch or fix is indicated for Red Hat Enterprise Linux 10 as it is not affected. Users should consult the vendor advisory for updates and avoid enabling systemd-homed-managed accounts on vulnerable builds.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-07-23T10:03:08.205Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-16743","vendor":"Red Hat"}]

Threat ID: 6a636e369c2644c7f806025e

Added to database: 07/24/2026, 13:52:54 UTC

Last enriched: 08/08/2026, 14:37:03 UTC

Last updated: 09/07/2026, 14:13:09 UTC

Views: 85

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses