A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade systemd | Apr 16, 2026 | Apr 16, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Mar 13, 2026 |
| Suse | — | Upgrade systemd-docUpgrade systemd-testsuiteUpgrade systemd-resolvedUpgrade systemd-experimentalUpgrade systemd-develUpgrade udevUpgrade systemd-bootUpgrade systemdUpgrade libsystemd0Upgrade systemd-sysvcompatUpgrade systemd-bash-completionUpgrade libudev1Upgrade libsystemd0-32bitUpgrade systemd-32bitUpgrade systemd-coredumpUpgrade systemd-langUpgrade systemd-networkUpgrade libudev1-32bitUpgrade libudev-develUpgrade systemd-homedUpgrade systemd-sysvinitUpgrade systemd-journal-remoteUpgrade systemd-containerUpgrade systemd-portableUpgrade systemd-networkd | Mar 27, 2026 | Mar 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub