SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16743

MEDIUM · CVSS 5.5 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

A vulnerability exists in the accountsservice where the systemd-homed code path for SetIconFile allows a local attacker with a managed account to open a user-supplied filename as root, bypassing necessary validation and privilege restrictions. This flaw could enable the attacker to read arbitrary files accessible to the accounts-daemon process, potentially exposing sensitive information. Organizations using systemd-homed should prioritize patching this vulnerability to mitigate the risk of local privilege escalation and data exposure.

CVE
CVE-2026-16743
Severity
MEDIUM
CVSS
5.5
EPSS
0.10%

Original NVD Description

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.