CVE-2026-83598
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-269
Gestión de privilegios incorrecta
Fecha de publicación:
22/09/2026
Última modificación:
23/09/2026
Descripción
*** Pendiente de traducción *** Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges. This vulnerability is fixed in 2.10.4.
Impacto
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://github.com/netdata/netdata/commit/d762782697623a98b51b4e41f7fe2d12404f0662
- https://github.com/netdata/netdata/pull/22751
- https://github.com/netdata/netdata/releases/tag/v2.10.4
- https://github.com/netdata/netdata/security/advisories/GHSA-8hxv-2mg6-ggw5
- https://github.com/netdata/netdata/security/advisories/GHSA-8hxv-2mg6-ggw5


