NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Vulnerability

A local privilege escalation vulnerability has been identified in NoMachine. This issue arises because the NoMachine Device Server loads a library from an unsecured location, allowing local attackers who can execute low-privileged code to escalate privileges and execute arbitrary code with SYSTEM rights.

Impact

Exploitation of this vulnerability allows for local privilege escalation, enabling an attacker to execute code with SYSTEM privileges.

Remediation

Users can upgrade to NoMachine version 9.4.14 to address this vulnerability.

Added: Apr 11, 2026, 1:20 AM
Updated: Apr 11, 2026, 1:20 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
10.0
exploitability
3.5
remediation
7.7
relevance
5.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.