CVE-2026-5055

7.8

NoMachine · Device Server

A local privilege escalation vulnerability exists in NoMachine Device Server due to an uncontrolled search path element, allowing low-privileged attackers to execute code as SYSTEM.

Executive summary

A critical local privilege escalation vulnerability in NoMachine Device Server allows low-privileged attackers to gain SYSTEM-level access to the host system.

Vulnerability

The flaw is an uncontrolled search path element (CWE-427) within the NoMachine Device Server, which improperly loads a library from an insecure location. This requires the attacker to have low-privileged access to the target system to trigger the escalation.

Business impact

Successful exploitation grants an attacker full SYSTEM-level privileges on the host machine. Given the CVSS score of 7.8 (High), this vulnerability poses a significant risk to organizational security, as it facilitates complete system compromise, potential data exfiltration, and the installation of persistent malicious software.

Remediation

Immediate Action: Update the NoMachine installation to the latest patched version provided by the vendor to resolve the library loading flaw.

Proactive Monitoring: Monitor system logs for unauthorized attempts to modify application files or unexpected process execution patterns originating from low-privileged accounts.

Compensating Controls: Restrict local user access to the file system where NoMachine binaries and configuration files are stored to prevent unauthorized library placement.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a high-severity risk due to the potential for full system takeover. Organizations currently running the affected version of NoMachine Device Server should prioritize the application of the vendor-provided patch immediately to prevent local privilege escalation attacks.

More NoMachine CVEs

Sources