
CVE-2026-40224 In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace. https://www.cve.org/CVERecord?id=CVE-2026-40224
Post summary
The post discloses a local privilege escalation vulnerability in systemd‑machined on versions 259 through 260, where varlink can access the root namespace, but it does not mention any PoC, exploit, or patch.
