Local Privilege Escalation Vulnerability in NoMachine Device Server
CVE-2026-5055

7.8HIGH

Key Information:

Vendor

Nomachine

Status
Vendor
CVE Published:
11 April 2026

What is CVE-2026-5055?

The NoMachine Device Server contains a vulnerability that permits local attackers to escalate their privileges due to an unsecured library loading process. This flaw enables an attacker, who has already executed low-privileged code on the machine, to exploit the vulnerability to gain higher-level access and run arbitrary code within the SYSTEM context. Proper defenses against such threats should be implemented to mitigate potential exploitation.

Affected Version(s)

NoMachine 9.2.18_1

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.