CVE-2026-83603

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata service account. The account can direct root fail2ban-client to a malicious UNIX socket, and fail2ban/client/csocket.py CSocket.receive() passes the returned data to pickle.loads(), allowing attacker-controlled code to execute as root on systems with fail2ban-client installed. This issue is fixed in version 2.10.4 and nightly build 2.10.0-782-nightly.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-04: 110-04
Referenced assets1 URL
By indicator
Full discourse1 post
  • Rıdvan Yağlı@ridvanyagli

    🔴 Netdata 2.10.4 öncesi sürümlerde, ndsudo içindeki fail2ban-client-status-socket işlevinde bulunan güvenlik açığı (CVE-2026-83603), düşük ayrıcalıklı yerel kullanıcının kötü amaçlı UNIX socket üzerinden root olarak kod çalıştırmasına olanak sağlıyor. CVSS: 8.4 (HIGH). Saldırı, Fail2Ban'ın güvensiz pickle.loads() kullanımının zincirlenmesiyle gerçekleşiyor. Etkisi: Local Privilege Escalation / Root RCE Bu açık için geçen ay PoC yayınlandı. https://github.com/OhWelp/CVE-2026-83603-LPE-PoC

    00121359
    2.4K followersView on X

Explore more