Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the l
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-83603 | 8.4 HIGH | Netdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCE |
| CVE-2026-83599 | 7.5 HIGH | Netdata: WebSocket Decompression Bomb |
| CVE-2026-83597 | 7.0 HIGH | Netdata: Local Privilege Escalation in Netdata Windows Agent installer via MSI Repair Exec |
| CVE-2026-83601 | 6.5 MEDIUM | Netdata: Streaming protocol dimension slot has no upper-bound guard, allowing integer over |
| CVE-2026-83602 | 6.5 MEDIUM | Netdata: Unauthenticated remote PUT to /api/v3/settings bypasses IP allowlist controls via |
| CVE-2026-83600 | 6.5 MEDIUM | Netdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB allocation request, |
No comments yet