CVE-2026-83597High· 7.0▾ TwilightNetdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A low-pr…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A low-privileged local user who triggers repair can interact with or hijack those visible process windows to execute arbitrary commands with SYSTEM privileges. This issue is fixed in stable version 2.10.4.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-83598High· 7.8Netdata is an open source observability tool
CVE-2026-83603High· 8.4Netdata is an open source observability tool
CVE-2026-83601Medium· 6.5Netdata is an open source observability tool
CVE-2026-83600Medium· 6.5Netdata is an open source observability tool
CVE-2026-83602Medium· 6.5Netdata is an open source observability tool
CVE-2026-83599High· 7.5Netdata is an open source observability tool