CVE-2026-18264
8.8NoMachine · NoMachine
NoMachine contains a command injection vulnerability in the getstat function, allowing an authenticated attacker to execute arbitrary system commands.
Executive summary
A critical command injection vulnerability in NoMachine allows authenticated remote attackers to achieve code execution.
Vulnerability
This vulnerability is an OS Command Injection (CWE-78) flaw residing in the getstat function. Based on the CVSS vector PR:L, this attack requires the user to be authenticated to the system to trigger the malicious payload.
Business impact
Successful exploitation of this flaw allows an attacker to execute arbitrary commands with the privileges of the NoMachine service. This can lead to full system compromise, unauthorized data access, and potential lateral movement within the network. With a CVSS score of 8.8, this represents a high risk to organizational security and infrastructure integrity.
Remediation
Immediate Action: Update NoMachine to the latest version as specified in the vendor advisory to patch the vulnerable getstat function.
Proactive Monitoring: Monitor system and application logs for unusual process execution patterns or unexpected shell commands originating from the NoMachine service account.
Compensating Controls: Ensure that access to the NoMachine interface is restricted to authorized users via network-level controls such as VPNs or firewalls to limit the attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this vulnerability necessitates immediate attention. Administrators should prioritize identifying instances of NoMachine version 9.7.3 within their environment and apply the necessary patches provided by the vendor. Delaying remediation increases the risk of unauthorized system access and potential exploitation by internal or compromised accounts.