CVE-2026-16743

Summary

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-269: Improper Privilege Management

Workarounds

Avoid using systemd-homed-managed accounts on systems running a vulnerable accountsservice build.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References