{"api_version":"1","generated_at":"2026-08-14T08:14:01+00:00","cve":"CVE-2026-15060","urls":{"html":"https://cve.report/CVE-2026-15060","api":"https://cve.report/api/cve/CVE-2026-15060.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-15060","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-15060"},"summary":{"title":"systemd-machined: unprivileged users can terminate arbitrary processes","description":"When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones.\n\n- versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file\n- versions older than v258 are not affected\n- unrelated to the systemd service manager (pid 1 or user session managers)\n- systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container)\n- terminal-only or remote sessions (e.g.: ssh) are not affected","state":"PUBLISHED","assigner":"systemd","published_at":"2026-08-10 14:17:21","updated_at":"2026-08-10 18:17:41"},"problem_types":["CWE-284","CWE-862","CWE-284 CWE-284","CWE-862 CWE-862"],"metrics":[{"version":"3.1","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","score":"4.7","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.7","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":4.7,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://github.com/systemd/systemd/security/advisories/GHSA-qwv4-3gwc-w5g8","name":"https://github.com/systemd/systemd/security/advisories/GHSA-qwv4-3gwc-w5g8","refsource":"98a521c5-3a3e-4e2b-bc27-002067e0463c","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-15060","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15060","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"systemd","product":"systemd-machined","version":"affected 259 262, 261.2, 260.4, 259.8, 258.10 custom","platforms":["Linux"]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"15060","cve":"CVE-2026-15060","epss":"0.000790000","percentile":"0.001700000","score_date":"2026-08-11","updated_at":"2026-08-12 00:06:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-15060","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-10T17:57:00.800960Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-10T17:57:14.676Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["Linux"],"product":"systemd-machined","repo":"https://github.com/systemd/systemd","vendor":"systemd","versions":[{"lessThan":"262, 261.2, 260.4, 259.8, 258.10","status":"affected","version":"259","versionType":"custom"}]}],"datePublic":"2026-08-10T13:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"When systemd-machined &gt;= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones.<br><br>- versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file<br>- versions older than v258 are not affected<br>- unrelated to the systemd service manager (pid 1 or user session managers)<br>- systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container)<br>- terminal-only or remote sessions (e.g.: ssh) are not affected"}],"value":"When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones.\n\n- versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file\n- versions older than v258 are not affected\n- unrelated to the systemd service manager (pid 1 or user session managers)\n- systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container)\n- terminal-only or remote sessions (e.g.: ssh) are not affected"}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":4.7,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-284","description":"CWE-284","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-862","description":"CWE-862","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-10T13:03:06.869Z","orgId":"98a521c5-3a3e-4e2b-bc27-002067e0463c","shortName":"systemd"},"references":[{"url":"https://github.com/systemd/systemd/security/advisories/GHSA-qwv4-3gwc-w5g8"}],"source":{"discovery":"EXTERNAL"},"title":"systemd-machined: unprivileged users can terminate arbitrary processes","x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"98a521c5-3a3e-4e2b-bc27-002067e0463c","assignerShortName":"systemd","cveId":"CVE-2026-15060","datePublished":"2026-08-10T13:03:06.869Z","dateReserved":"2026-07-08T14:15:06.476Z","dateUpdated":"2026-08-10T17:57:14.676Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 14:17:21","lastModifiedDate":"2026-08-10 18:17:41","problem_types":["CWE-284","CWE-862","CWE-284 CWE-284","CWE-862 CWE-862"],"metrics":{"cvssMetricV31":[{"source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-10T17:57:00.800960Z","id":"CVE-2026-15060","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"15060","Ordinal":"1","Title":"systemd-machined: unprivileged users can terminate arbitrary pro","CVE":"CVE-2026-15060","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"15060","Ordinal":"1","NoteData":"When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones.\n\n- versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file\n- versions older than v258 are not affected\n- unrelated to the systemd service manager (pid 1 or user session managers)\n- systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container)\n- terminal-only or remote sessions (e.g.: ssh) are not affected","Type":"Description","Title":"systemd-machined: unprivileged users can terminate arbitrary pro"}]}}}