Skip to content
Red HatCVE-2026-16743

Red Hat accountsservice: improper privilege management

Medium5.5CVE-2026-16743 · Published Jul 24, 2026

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat libsoup: request smuggling
Medium5.4Jul 24
Red Hat libsoup: information disclosure
Medium6.5Jul 24
Red Hat libsoup. An unsigned integer underflow: integer overflow
Medium6.5Jul 24
A flaw was found in the cluster-proxy service-proxy component used in Red Hat...
High8.5Jul 24
Red Hat pki-core: improper authorization
Low3.1Jul 24
Red Hat role-users endpoint: insecure direct object reference
Medium6.5Jul 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.