{"id":"AZL-94088","summary":"CVE-2026-16743 affecting package accountsservice 23.13.9-1","details":"A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.","modified":"2026-09-02T05:29:58Z","published":"2026-07-24T13:17:27Z","upstream":["CVE-2026-16743"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16743"}],"affected":[{"package":{"name":"accountsservice","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/accountsservice"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"23.13.9-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94088.json"}}],"schema_version":"1.9.0"}