CVE-2026-40228
LOWsystemd 259 - Unauthenticated Terminal Injection via ANSI Escape Sequences
Title source: llmDescription
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
References (2)
Core 2
Core References
Scores
CVSS v3
2.9
EPSS
0.0017
EPSS Percentile
7.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-669
Status
published
Products (2)
systemd/systemd
259
systemd_project/systemd
259
Published
Apr 10, 2026
Tracked Since
Apr 10, 2026