Executive brief
Netdata, an open-source monitoring platform, exposes a settings configuration endpoint without proper authentication controls. An attacker on the network can send unauthenticated requests to modify stored settings and consume disk space by writing large files, bypassing IP-based access restrictions that administrators intended to enforce.
Technical details
The /api/v3/settings endpoint in Netdata 2.0.0 through 2.10.x was registered with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, allowing unauthenticated PUT requests to bypass IP allowlists configured via the dashboard access policy. An attacker can persist arbitrary JSON to {varlib}/settings/default.json, manipulate version counters, and perform repeated ~20 MiB writes for disk exhaustion, though this does not affect collection or security policies.
Affected products
- Netdata Netdata 2.0.0 to 2.10.x
Timeline
- 2026-09-22: disclosed
- 2026-07-09: patched: Fix merged to master via PR #22896, released in 2.11.0