ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability
ZDI disclosed CVE-2026-92210, an unauthenticated server-side request forgery in NoMachine's nxhtd server leading to information disclosure (CVSS 7.2).
ZDI published advisory ZDI-26-712 describing a server-side request forgery vulnerability in NoMachine's nxhtd server, tracked as CVE-2026-92210 with CVSS 7.2. Remote attackers can initiate arbitrary server-side requests without authentication, resulting in information disclosure. The advisory does not state whether exploitation has been observed or a patch released.
- SSRF in NoMachine nxhtd server, CVE-2026-92210
- Authentication not required, CVSS 7.2
- Enables arbitrary server-side requests and information disclosure
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92210 | NVD description · AI analysis pending | — | — | — | — | — |
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-92210.
This source does not provide full text. Read it at zerodayinitiative.com.