High severity7.8NVD Advisory· Published Sep 22, 2026
CVE-2026-83598
CVE-2026-83598
Description
Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges. This vulnerability is fixed in 2.10.4.
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.