CVE-2026-53694
Received Received - Intake
Improper Argument Injection in NoMachine

Publication date: 2026-06-10

Last updated on: 2026-06-10

Assigner: 5a6e4751-2f3f-4070-9419-94fb35b644e8

Description
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before 9.5.7, before 8.23.2.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-10
Last Modified
2026-06-10
Generated
2026-06-10
AI Q&A
2026-06-10
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
nomachine nomachine to 9.5.7|end_excluding=8.23.2 (exc)
nomachine nomachine to 9.5.7 (exc)
nomachine nomachine to 8.23.2 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is an Improper Neutralization of Argument Delimiters in a Command, also known as 'Argument Injection', found in Nomachine software versions before 9.5.7 and before 8.23.2.

It allows an attacker to inject malicious arguments into commands executed by the software, potentially altering the intended behavior of those commands.

Impact Analysis

The vulnerability can lead to potential local privilege escalation on Windows systems by exploiting the argument injection flaw in the nxchmod.sh script.

This means an attacker with limited privileges could gain higher-level access, compromising system security and control.

Mitigation Strategies

To mitigate the vulnerability in NoMachine related to argument injection, you should update your NoMachine software to version 9.5.7 or later (for versions before 9.5.7) or at least version 8.23.2 (for versions before 8.23.2). These updates address the security issues including the argument injection vulnerability and include updated third-party components such as OpenSSL 3.0.20 and Apache httpd 2.4.67.

Ensure that you download the updates from the official NoMachine website or your User Area if you have a valid subscription. Follow the provided manual installation instructions for your operating system (Windows, macOS, Linux) or use the automatic update feature which checks for new versions every two days.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53694. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart