CVE-2026-15060Disclosure

LOWCVSS 4.7 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file - versions older than v258 are not affected - unrelated to the systemd service manager (pid 1 or user session managers) - systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container) - terminal-only or remote sessions (e.g.: ssh) are not affected

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-10: 2Technical Details · 2026-08-10: 208-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-15060 When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logge… https://www.cve.org/CVERecord?id=CVE-2026-15060

    Post summary

    The excerpt announces CVE‑2026‑15060, noting that an unprivileged user on a desktop running recent systemd‑machined versions can exploit a privilege mechanism, but it lacks any PoC, exploit code, or patch details.

    00001979
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-15060 When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logge… https://www.cve.org/CVERecord?id=CVE-2026-15060 ----- Traducción: CVE-2026-15060 Cua… http://infoflow.cloud`

    Post summary

    A brief notice alerting about CVE-2026-15060, detailing affected systemd-machined versions and conditions, but lacking any PoC, exploitation evidence, or patch info.

    0000034
    98 followersView on X

Explore more