Privilege Escalation in Netdata Windows Agent MSI Repair
CVE-2026-83598
7.8HIGH
What is CVE-2026-83598?
The Netdata Windows Agent, versions 2.0.0 through 2.10.4, contains a privilege escalation vulnerability that occurs during the MSI repair process. When initiated, the powershell.exe runs with SYSTEM privileges, enabling execution of commands from a profile located in the low-privileged user's Documents directory. This can potentially allow an attacker to execute arbitrary code at a higher privilege level. The vulnerability is addressed in version 2.10.4, which mitigates these risks.
Affected Version(s)
netdata >= 2.0.0, < 2.10.4
