CVE-2026-4105
published 2026-03-13CVE-2026-4105: A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class…
PriorityP336medium6.7CVSS 3.1
AVLACHPRLUIRSUCHIHAH
EPSS
0.14%
3.9th percentile
A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | systemd | < systemd 260~rc3-1 (forky) | systemd 260~rc3-1 (forky) |
| msrc | azl3_systemd-bootstrap_250.3-18_on_azure_linux_3.0 | — | — |
| msrc | azl3_systemd_255-26_on_azure_linux_3.0 | — | — |
| msrc | cbl2_systemd-bootstrap_250.3-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_systemd_250.3-23_on_cbl_mariner_2.0 | — | — |
| systemd_project | systemd | >= 0 < 260~rc3-1 | 260~rc3-1 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_msrc6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-4105: A flaw was found in systemd
osv·2026-03-13·CVSS 6.7
CVE-2026-4105 [MEDIUM] CVE-2026-4105: A flaw was found in systemd
A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.
Red Hat
systemd: systemd: Privilege escalation via improper access control in RegisterMachine D-Bus method
vendor_redhat·2026-03-13·CVSS 6.7
CVE-2026-4105 [MEDIUM] CWE-284 systemd: systemd: Privilege escalation via improper access control in RegisterMachine D-Bus method
systemd: systemd: Privilege escalation via improper access control in RegisterMachine D-Bus method
A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.
A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class
Microsoft
Systemd: systemd: privilege escalation via improper access control in registermachine d-bus method
vendor_msrc·2026-03-10·CVSS 6.7
CVE-2026-4105 [MEDIUM] CWE-284 Systemd: systemd: privilege escalation via improper access control in registermachine d-bus method
Systemd: systemd: privilege escalation via improper access control in registermachine d-bus method
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Debian
CVE-2026-4105: systemd - A flaw was found in systemd. The systemd-machined service contains an Improper A...
vendor_debian·2026·CVSS 6.7
CVE-2026-4105 [MEDIUM] CVE-2026-4105: systemd - A flaw was found in systemd. The systemd-machined service contains an Improper A...
A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 260~rc3-1)
sid: resolved (fixed in 260~rc3-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-4105 systemd: systemd: Privilege escalation via improper access control in RegisterMachine D-Bus method
bugzilla·2026-03-13·CVSS 6.7
CVE-2026-4105 [MEDIUM] CVE-2026-4105 systemd: systemd: Privilege escalation via improper access control in RegisterMachine D-Bus method
CVE-2026-4105 systemd: systemd: Privilege escalation via improper access control in RegisterMachine D-Bus method
HASH(0x5581fd0f1a10)
Wiz
CVE-2026-4105 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2026-4105 [CRITICAL] CVE-2026-4105 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4105 :
Wolfi vulnerability analysis and mitigation
A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.
Source : NVD
## 6.7
Score
Published March 13, 2026
Severity MEDIUM
CNA Score 6.7
Affected Technologies
Wolfi
Chainguard
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV
2026-03-13
Published