Junglewise Threat Intelligence

CVE-2026-5055: NoMachine privilege escalation in Device Server

CVE-2026-5055 · Severity: high · CVSS 7.8 · Published 2026-04-11

Technologies: Nomachine. Vendors: Nomachine.

Executive brief

NoMachine is a remote desktop and connectivity tool used to access computers over a network. A security flaw in the NoMachine Device Server allows a user who already has limited access to a computer to gain full administrative (SYSTEM) control. This could allow an attacker to bypass security restrictions, access sensitive data, or install malicious software on the affected machine.

Technical details

A local privilege escalation vulnerability exists in the NoMachine Device Server due to an uncontrolled search path element (CWE-427). The application attempts to load a library from an unsecured location, which can be manipulated by a local user. An attacker with low-privileged code execution capabilities on the target system can place a malicious DLL or library in the expected path. When the service loads the library, it executes the attacker's code with SYSTEM-level privileges. This vulnerability is addressed in NoMachine version 9.4.14.

Affected products

  • NoMachine NoMachine versions prior to 9.4.14

Timeline

  • 2025-12-24: other: Vulnerability reported to vendor
  • 2026-03-30: patched: Fixed in NoMachine version 9.4.14
  • 2026-03-30: advisory: Coordinated public release by ZDI
  • 2026-04-11: disclosed: NVD publication date

References

Related threats