Arbitrary File Deletion Vulnerability in NoMachine Software
CVE-2026-5053
7.1HIGH
What is CVE-2026-5053?
The NoMachine software contains a vulnerability that allows local attackers to delete arbitrary files by exploiting improper validation of environment variables. An attacker needs to execute low-privileged code on the target system to exploit this weakness. By supplying a malicious path, the attacker can perform file operations in the context of root, potentially leading to a significant compromise of the system's integrity and data security.
Affected Version(s)
NoMachine 9.3.7
