---
id: CVE-2026-53694
title: >-
  Improper Neutralization of Argument Delimiters in a Command ('Argument
  Injection') vulnerability in Nomachine allows Argument Injection.This issue
  affects Nomachine: before 9.5.7, before 8.23.2.
summary: >-
  Improper Neutralization of Argument Delimiters in a Command ('Argument
  Injection') vulnerability in Nomachine allows Argument Injection.This issue
  affects Nomachine: before 9.5.7, before 8.23.2.
severity: none
cwe:
  - CWE-88
published: '2026-06-10'
updated: '2026-07-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53694'
references:
  - url: 'https://kb.nomachine.com/SU05X00274'
    label: 5a6e4751-2f3f-4070-9419-94fb35b644e8
  - url: 'https://kb.nomachine.com/SU05X00275'
    label: 5a6e4751-2f3f-4070-9419-94fb35b644e8
tags:
  - nvd
  - exploit-available
epss: 0.00188
epssPercentile: 0.07409
ingestedAt: '2026-07-07T16:25:59.281Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/do4choo/CVE-2026-53694-NoMachine-LPE'
  checkedAt: '2026-09-25T08:21:02.246Z'
exploitAvailable: true
---

## Overview

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before 9.5.7, before 8.23.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
