CVE-2026-5055
7.8NoMachine · Device Server
A local privilege escalation vulnerability exists in NoMachine Device Server due to an uncontrolled search path element, allowing low-privileged attackers to execute code as SYSTEM.
Executive summary
A critical local privilege escalation vulnerability in NoMachine Device Server allows low-privileged attackers to gain SYSTEM-level access to the host system.
Vulnerability
The flaw is an uncontrolled search path element (CWE-427) within the NoMachine Device Server, which improperly loads a library from an insecure location. This requires the attacker to have low-privileged access to the target system to trigger the escalation.
Business impact
Successful exploitation grants an attacker full SYSTEM-level privileges on the host machine. Given the CVSS score of 7.8 (High), this vulnerability poses a significant risk to organizational security, as it facilitates complete system compromise, potential data exfiltration, and the installation of persistent malicious software.
Remediation
Immediate Action: Update the NoMachine installation to the latest patched version provided by the vendor to resolve the library loading flaw.
Proactive Monitoring: Monitor system logs for unauthorized attempts to modify application files or unexpected process execution patterns originating from low-privileged accounts.
Compensating Controls: Restrict local user access to the file system where NoMachine binaries and configuration files are stored to prevent unauthorized library placement.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability represents a high-severity risk due to the potential for full system takeover. Organizations currently running the affected version of NoMachine Device Server should prioritize the application of the vendor-provided patch immediately to prevent local privilege escalation attacks.