Unauthenticated PUT Request Vulnerability in Netdata Open Source Tool
CVE-2026-83602

6.5MEDIUM

Key Information:

Vendor

Netdata

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-83602?

An unauthenticated PUT request vulnerability in the Netdata observability tool allows a malicious actor to bypass IP restrictions set by operators. By making use of the /api/v3/settings endpoint, attackers can write malicious JSON data into the {varlib}/settings/default.json file, leading to potential disk space exhaustion through repeated large writes. While this file does not directly control the security policy or data collection, the implications of such an attack can lead to significant operational disruptions. This issue has been addressed in version 2.11.0.

Affected Version(s)

netdata >= 2.0.0, < 2.11.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.