Arbitrary Process Termination in systemd-machined by Unprivileged Users
CVE-2026-15060
4.7MEDIUM
What is CVE-2026-15060?
A vulnerability in systemd-machined allows unprivileged users logged into a graphical desktop session to terminate any process, including privileged ones, if running version v259 or later (or version v258 with specific custom polkit policies). Systems with versions older than v259 are generally safe unless custom configurations grant unprivileged access to the register-machine action in polkit. Note that this issue is not associated with the systemd service manager and is typically found in optional packages. Sessions that are terminal-only or remote do not face this vulnerability.
Affected Version(s)
systemd-machined Linux 259 < 262, 261.2, 260.4, 259.8, 258.10
