Executive brief
NoMachine is a remote desktop tool used to access computers and manage servers remotely. A security flaw in how the software handles file paths allows a user who already has limited access to the computer to gain full administrative (root) control. This could allow an unauthorized person to take complete control of the system, access sensitive data, or disrupt operations.
Technical details
A local privilege escalation vulnerability exists in NoMachine due to improper validation of user-supplied file paths in command line parameters (CWE-73). The flaw occurs when the application performs file operations using these unvalidated paths, allowing an attacker with low-privileged access to manipulate the execution flow. By exploiting this lack of path validation, an attacker can execute arbitrary code with root-level privileges. The vulnerability is addressed in NoMachine version 9.4.14. Exploitation requires the attacker to have existing local access to execute code on the target system.
Affected products
- NoMachine NoMachine versions prior to 9.4.14
Timeline
- 2026-02-06: other: Vulnerability reported to vendor
- 2026-03-30: patched: Coordinated public release of advisory and fix in version 9.4.14
- 2026-04-11: disclosed: NVD publication date