ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability

mediumVulnerabilityimportance 25CVE-2026-92209
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-92209, an improper authentication flaw in NoMachine's bundled Redis component allowing local privilege escalation (CVSS 7.8).

ZDI published advisory ZDI-26-711 describing an improper authentication vulnerability in the Redis component bundled with NoMachine, tracked as CVE-2026-92209 with CVSS 7.8. A local attacker who can already execute low-privileged code on the target system can escalate privileges. No in-the-wild exploitation or patch details are mentioned in the advisory.

  • Improper authentication in NoMachine's bundled Redis, CVE-2026-92209
  • Local privilege escalation rated CVSS 7.8
  • Requires prior low-privileged code execution on the target

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-92209

NVD description · AI analysis pending
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92209.

This source does not provide full text. Read it at zerodayinitiative.com.