ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability
ZDI disclosed CVE-2026-92209, an improper authentication flaw in NoMachine's bundled Redis component allowing local privilege escalation (CVSS 7.8).
ZDI published advisory ZDI-26-711 describing an improper authentication vulnerability in the Redis component bundled with NoMachine, tracked as CVE-2026-92209 with CVSS 7.8. A local attacker who can already execute low-privileged code on the target system can escalate privileges. No in-the-wild exploitation or patch details are mentioned in the advisory.
- Improper authentication in NoMachine's bundled Redis, CVE-2026-92209
- Local privilege escalation rated CVSS 7.8
- Requires prior low-privileged code execution on the target
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92209 | NVD description · AI analysis pending | — | — | — | — | — |
This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92209.
This source does not provide full text. Read it at zerodayinitiative.com.