PT-2026-96844 · Netdata · Netdata Windows Agent

CVE-2026-83598

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netdata versions 2.0.0 through 2.10.3
Description During the MSI repair process of the Netdata Windows Agent, powershell.exe is executed with SYSTEM privileges without the -NoProfile flag. This causes the system to load the Microsoft.PowerShell profile.ps1 file from the %USERPROFILE%DocumentsWindowsPowerShell directory of the low-privileged user who started the repair. Consequently, any commands placed within that profile by the user are executed with elevated SYSTEM privileges.
Recommendations Update to version 2.10.4.

Exploit

Fix

Improper Privilege Management

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-83598
GHSA-8HXV-2MG6-GGW5

Affected Products

Netdata Windows Agent