What is CVE-2026-16743?
CVE-2026-16723 is a vulnerability in accountsservice where the systemd-homed code path for SetIconFile opens a user-supplied filename as root without proper validation. A local attacker with a systemd-homed-managed account can exploit this to read arbitrary files accessible to the account.
Azərbaycanca: CVE-2026-16723 accountsservice-də tapılmış boşluqdur. systemd-homed ilə idarə olunan hesablarda SetIconFile funksiyası root kimi işləyərək fayl yolunu düzgün yoxlamır, bu da lokal hücumçuya hesabın əlçatan olduğu ixtiyari faylları oxumağa imkan verir.
Related CVEs
link basis: same weakness class CWE-22
FAQ1
What is the vulnerability in CVE-2026-16723?
It is a vulnerability in accountsservice where the systemd-homed code path for SetIconFile opens a user-supplied filename as root without proper validation. A local attacker with a systemd-homed-managed account can exploit this to read arbitrary files accessible to the account.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.