CVE-2026-83598

HIGH CVSS 3.1: 7.8 EPSS 0.16%
Updated Sep 23, 2026
Microsoft
Parameter Value
CVSS 7.8 (HIGH)
Fixed In 2.10.4
Type CWE-427 (Uncontrolled Search Path Element), CWE-269 (Improper Privilege Management)
Vendor Microsoft
Public PoC No

Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges.

This vulnerability is fixed in 2.10.4.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1