Junglewise Threat Intelligence

CVE-2026-53694: NoMachine privilege escalation via argument injection in nxchmod.sh

CVE-2026-53694 · Severity: info · CVSS 7.3 · Published 2026-06-10

Technologies: Nomachine. Vendors: Nomachine.

Executive brief

NoMachine, a remote desktop and remote access tool, contains a vulnerability that could allow a local user to gain elevated system privileges. By exploiting a flaw in how the software handles specific internal scripts, an attacker with limited access to a computer could potentially take full control of the system. This could lead to unauthorized access to sensitive data or the disruption of business operations on the affected machine.

Technical details

An argument injection vulnerability exists in NoMachine due to improper neutralization of argument delimiters within the 'nxchmod.sh' script. A local attacker with low-level privileges can exploit this flaw by passing specially crafted arguments to the script, leading to execution of commands with elevated permissions (Privilege Escalation). The vulnerability is reachable locally and does not require user interaction, though it may depend on specific environmental preconditions. The issue is resolved in NoMachine versions 9.5.7 and 8.23.2.

Affected products

  • NoMachine NoMachine before 9.5.7, before 8.23.2

Timeline

  • 2026-05-07: patched: NoMachine versions 9.5.7 and 8.23.2 released
  • 2026-06-10: disclosed: CVE-2026-53694 published

References

Related threats