CVE-2026-83597
Received Received - Intake

Netdata Windows Agent MSI Repair Privilege Escalation

Vulnerability report for CVE-2026-83597, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: GitHub, Inc.

Description

Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A low-privileged local user who triggers repair can interact with or hijack those visible process windows to execute arbitrary commands with SYSTEM privileges. This issue is fixed in stable version 2.10.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
netdata netdata to 2.10.4 (inc)
netdata netdata From 2.0.0 (inc) to 2.10.4 (exc)
netdata netdata From 1.99.0-458 (inc) to 23.10.0-781 (exc)
netdata netdata 2.10.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a privilege escalation issue in the Netdata Windows Agent installer (MSI package) affecting versions between 2.0.0 and 2.10.3. During the MSI repair process, powershell.exe and wevtutil.exe are launched as elevated interactive processes in the user's desktop session. A low-privileged local attacker can hijack these visible processes to execute arbitrary commands with SYSTEM privileges.

Detection Guidance

Check for Netdata Windows Agent versions between 2.0.0 and 2.10.3 or nightly builds between v1.99.0-458 and v23.10.0-781. Look for suspicious powershell.exe or wevtutil.exe processes spawned during MSI repair in C:\Windows\Installer. Monitor for unexpected SYSTEM-level command prompts or process hijacking attempts.

Impact Analysis

A local attacker with low privileges could gain full SYSTEM-level access to the affected machine. This could allow them to install malware, modify system files, create new user accounts, or perform other actions with complete control over the system.

Compliance Impact

This vulnerability could lead to unauthorized access and control of systems, which may violate compliance requirements for data protection and system integrity under standards like GDPR and HIPAA. Unauthorized privilege escalation could result in data breaches or system compromise, triggering regulatory penalties and compliance violations.

Mitigation Strategies

Upgrade Netdata Windows Agent to version 2.10.4 or later. Remove cached MSI files in C:\Windows\Installer if repair is unnecessary. Restrict local user access to MSI repair operations and monitor for unauthorized process execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83597. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart