๐Ÿ” CVE Alert

CVE-2026-83603

HIGH 8.4

Netdata: Local Root via ndsudo Arbitrary socket_path โ†’ fail2ban-client Pickle RCE

CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th

Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata service account. The account can direct root fail2ban-client to a malicious UNIX socket, and fail2ban/client/csocket.py CSocket.receive() passes the returned data to pickle.loads(), allowing attacker-controlled code to execute as root on systems with fail2ban-client installed. This issue is fixed in version 2.10.4 and nightly build 2.10.0-782-nightly.

CWE CWE-73 CWE-502
Vendor netdata
Product netdata
Published Sep 22, 2026
Last Updated Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for netdata netdata

Be the first to know when new high vulnerabilities affecting netdata netdata are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

netdata / netdata
< 2.10.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/netdata/netdata/security/advisories/GHSA-qwh9-pq27-993w github.com: https://github.com/netdata/netdata/pull/22745 github.com: https://github.com/netdata/netdata/commit/9bced8d46464bd0fe01b0b5f8c63c4ac24e9b060 github.com: https://github.com/netdata/netdata/releases/tag/v2.10.4