← All Advisories

CVE-2026-83598

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-83598

Key Details

CVECVE-2026-83598
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsnetdata netdata
Classified asCWE-269 (Improper Privilege Management)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
netdatanetdata
SubsystemsGeneral OT
SectorsMultiple

What to Know

Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges. This vulnerability is fixed in 2.10.4. (NVD)

What to Do

Monitor netdata's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-83598
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-83598