CVE-2026-83598
Netdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Profile Hijack in MSI Repair
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th
Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges. This vulnerability is fixed in 2.10.4.
| CWE | CWE-269 CWE-427 |
| Vendor | netdata |
| Product | netdata |
| Published | Sep 22, 2026 |
| Last Updated | Sep 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for netdata netdata
Be the first to know when new high vulnerabilities affecting netdata netdata are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
netdata / netdata
>= 2.0.0, < 2.10.4
References
github.com: https://github.com/netdata/netdata/security/advisories/GHSA-8hxv-2mg6-ggw5 github.com: https://github.com/netdata/netdata/pull/22751 github.com: https://github.com/netdata/netdata/commit/d762782697623a98b51b4e41f7fe2d12404f0662 github.com: https://github.com/netdata/netdata/releases/tag/v2.10.4