Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A low-privileged local user who
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-83603 | 8.4 HIGH | Netdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCE |
| CVE-2026-83598 | 7.8 HIGH | Netdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Prof |
| CVE-2026-83599 | 7.5 HIGH | Netdata: WebSocket Decompression Bomb |
| CVE-2026-83601 | 6.5 MEDIUM | Netdata: Streaming protocol dimension slot has no upper-bound guard, allowing integer over |
| CVE-2026-83602 | 6.5 MEDIUM | Netdata: Unauthenticated remote PUT to /api/v3/settings bypasses IP allowlist controls via |
| CVE-2026-83600 | 6.5 MEDIUM | Netdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB allocation request, |
No comments yet