Vulnerability Details CVE-2026-40224
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 0.2%
CVSS Severity
CVSS v3 Score 6.7
Products affected by CVE-2026-40224
-
cpe:2.3:a:systemd_project:systemd:259
-
cpe:2.3:a:systemd_project:systemd:259.1
-
cpe:2.3:a:systemd_project:systemd:259.2