CVE-2026-4105: Red Hat Enterprise Linux 10

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.

Affected products

  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Hardened Images: before 260.1-2.1.hum1 (fixed in 260.1-2.1.hum1)
  • Red Hat Red Hat Openshift Container Platform 4

Published 2026-03-13. Last modified 2026-09-01.