Executive brief
A vulnerability in NoMachine, a remote desktop and access software, allows a local user with limited permissions to delete any file on the system. By manipulating specific settings, an attacker can force the application to delete critical system files or application data that would normally be protected. This could lead to a total system failure, loss of important data, or the disruption of business operations.
Technical details
An arbitrary file deletion vulnerability exists in NoMachine due to the external control of file paths (CWE-73). The flaw is located in the handling of environment variables, where the application fails to properly validate user-supplied paths before using them in file operations. A local attacker with low-privileged access can manipulate these environment variables to trigger file deletions with root-level privileges. This can be used to delete critical system files or configuration data. The issue is resolved in NoMachine version 9.4.14.
Affected products
- NoMachine NoMachine versions prior to 9.4.14
Timeline
- 2026-02-06: disclosed: Vulnerability reported to vendor
- 2026-03-30: patched: Fixed in NoMachine version 9.4.14
- 2026-03-30: advisory: Coordinated public release of advisory by ZDI
- 2026-04-11: advisory: NVD publication date