CVE-2026-4105: Red Hat Enterprise Linux 10
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Hardened Images: before 260.1-2.1.hum1 (fixed in 260.1-2.1.hum1)
- Red Hat Red Hat Openshift Container Platform 4
Published 2026-03-13. Last modified 2026-09-01.