NoMachine Privilege Escalation Vulnerability via External Control of File Path

Vulnerability

A local privilege escalation vulnerability has been identified in NoMachine. This issue arises from improper validation of user-supplied paths in command line parameters, allowing local attackers with low-privileged code execution to escalate privileges and execute arbitrary code as root.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling local attackers to execute arbitrary code with root privileges.

Remediation

Users can upgrade to NoMachine version 9.4.14 to address this vulnerability.

Added: Apr 11, 2026, 1:20 AM
Updated: Apr 11, 2026, 1:20 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
3.5
remediation
7.7
relevance
5.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.