Junglewise Threat Intelligence

CVE-2026-83598: Netdata Windows Agent MSI privilege escalation during repair

CVE-2026-83598 · Severity: high · CVSS 7.8 · Published 2026-09-22

Vendors: Netdata.

Executive brief

Netdata's Windows agent installer can be abused during repair operations to execute arbitrary commands with SYSTEM-level privileges. An attacker with access to a user's local machine can plant malicious PowerShell commands that execute with elevated rights when an administrator initiates an MSI repair, leading to full system compromise and potential installation of ransomware or persistent malware.

Technical details

During MSI repair, powershell.exe is launched as SYSTEM without the -NoProfile flag, causing it to load the user's PowerShell profile from %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1. A low-privileged attacker can pre-populate this profile with arbitrary commands that execute with SYSTEM privileges when a repair is triggered. This is a local privilege escalation requiring user interaction (repair initiation) by an administrator.

Affected products

  • Netdata Windows Agent 2.0.0 through 2.10.3

Timeline

  • 2026-09-22: disclosed
  • 2026-06-17: patched: Fixed in version 2.10.4

References

Related threats