systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.
Conclusion & alert: CVE-2023-26604 is rated High Exploit Risk (78.4/100): CVSS High severity, with high exploitation likelihood (EPSS 5.63%, 90th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-21 | 5.01% | 5.63% | +0.62% |
| 2 | 2025-12-28 | 4.72% | 5.01% | +0.29% |
| 3 | 2025-11-21 | — | 4.72% | — |
Full EPSS history (21 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2023-26604 not yet assigned priority: Debian including 1 source packages (systemd), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2023-26604 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2023-26604 |
suse
|
high | CVE-2023-26604 severity important: SUSE including 329 source package names (14.2-3.13.134:libsystemd0-246.16-150300.7.60.1, 14.2-3.13.134:libudev1-246.16-150300.7.60.1, …), 885 product×package rows across 76 product lines (Container suse/ltss/sle12.5/sles12sp5, Container suse/sle-micro-rancher/5.2, … (76 product lines)): Known Not Affected 332, Fixed 322, Known Affected 231. | https://www.suse.com/security/cve/CVE-2023-26604/ |
ubuntu
|
low | CVE-2023-26604 low priority: Ubuntu including 1 source packages (systemd), 13 status rows across 13 suites (bionic, focal, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 8, needs-triage 3, needed 2. | https://ubuntu.com/security/CVE-2023-26604 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| systemd_project | systemd | < 246.7 | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://packetstormsecurity.com/files/174130/systemd-246-Local-Root-Privilege-Escalation.html | Exploit Third Party Advisory |
| https://blog.compass-security.com/2012/10/dangerous-sudoers-entries-part-2-insecure-functionality/ | Exploit Third Party Advisory |
| https://github.com/systemd/systemd/blob/main/NEWS#L4335-L4340 | Release Notes |
| https://lists.debian.org/debian-lts-announce/2023/03/msg00032.html | Mailing List Third Party Advisory |
| https://medium.com/%40zenmoviefornotification/saidov-maxim-cve-2023-26604-c1232a526ba7 | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20230505-0009/ | Third Party Advisory |