CVE-2026-16742: systemd-homed: local privilege escalation via missing home-record signature verification on the authenticate path
Published Aug 10, 2026
·Updated
systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user
Event History
Aug 10, 2026
CVE Published
via MITRE·01:02 PM
Data Sourced
via MITRE·01:02 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-16742?
CVE-2026-16742 has a medium severity score of 6.7.
2
What does CVE-2026-16742 affect?
CVE-2026-16742 affects systemd-homed and allows local privilege escalation due to missing home-record signature verification.
3
How do I mitigate CVE-2026-16742?
To mitigate CVE-2026-16742, ensure that your systemd-homed is updated to the latest version that addresses this vulnerability.
4
What is the risk of CVE-2026-16742 on my system?
CVE-2026-16742 presents a risk score of 59, indicating potential for local privilege escalation if exploited.
5
Who is affected by CVE-2026-16742?
CVE-2026-16742 affects local, logged in users who are managed by homed in systemd.