Local Privilege Escalation in systemd-homed by systemd
CVE-2026-16742

6.7MEDIUM

Key Information:

Vendor

Systemd

Vendor
CVE Published:
10 August 2026

What is CVE-2026-16742?

A local privilege escalation vulnerability exists in systemd-homed that allows an attacker with access to a logged-in homed-managed user to add arbitrary system groups. This flaw could be exploited to gain elevated privileges on the system, enabling unauthorized actions within the security context of an elevated user.

Affected Version(s)

systemd-homed Linux 245 < 262, 261.2, 260.4, 259.8, 258.10

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.