Junglewise Threat Intelligence

CVE-2026-83602: Netdata API access control bypass in /api/v3/settings

CVE-2026-83602 · Severity: medium · CVSS 6.5 · Published 2026-09-22

Technologies: Netdata. Vendors: Netdata.

Executive brief

Netdata, an open-source monitoring platform, exposes a settings configuration endpoint without proper authentication controls. An attacker on the network can send unauthenticated requests to modify stored settings and consume disk space by writing large files, bypassing IP-based access restrictions that administrators intended to enforce.

Technical details

The /api/v3/settings endpoint in Netdata 2.0.0 through 2.10.x was registered with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, allowing unauthenticated PUT requests to bypass IP allowlists configured via the dashboard access policy. An attacker can persist arbitrary JSON to {varlib}/settings/default.json, manipulate version counters, and perform repeated ~20 MiB writes for disk exhaustion, though this does not affect collection or security policies.

Affected products

  • Netdata Netdata 2.0.0 to 2.10.x

Timeline

  • 2026-09-22: disclosed
  • 2026-07-09: patched: Fix merged to master via PR #22896, released in 2.11.0

References

Related threats