CVE-2026-5054
Homebrew vulnerability analysis and mitigation

Overview

CVE-2026-5054 is a local privilege escalation vulnerability in NoMachine caused by improper validation of user-supplied file paths in command line parameter handling. It was reported to the vendor on February 6, 2026, and publicly disclosed on March 30, 2026, via a coordinated Zero Day Initiative advisory. All NoMachine versions prior to 9.4.14 are affected. The vulnerability carries a CVSS v3 base score of 7.8 (High) (ZDI Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-73 (External Control of File Name or Path), where NoMachine fails to properly validate user-supplied paths before using them in file system operations triggered via command line parameters. An attacker with low-privileged local code execution can supply a crafted path argument that is consumed by a privileged NoMachine process without sanitization, enabling manipulation of file operations in a privileged context. This allows the attacker to escalate privileges and execute arbitrary code as root. No public proof-of-concept exploit code has been released; the ZDI advisory (ZDI-CAN-28630) is informational only (ZDI Advisory, GitHub Advisory).

Impact

Successful exploitation grants a low-privileged local attacker full root-level code execution on the affected system, resulting in complete compromise of confidentiality, integrity, and availability. An attacker achieving root access could read or exfiltrate sensitive data, modify system files, install persistent backdoors, and use the compromised host as a pivot point for lateral movement within the network (ZDI Advisory).

Exploitability

No confirmed in-the-wild exploitation has been observed, and no functional exploit code is publicly available — the ZDI advisory is classified as informational rather than a working exploit (ZDI Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.015–0.019%, indicating a low near-term exploitation probability (GitHub Advisory). Exploitation requires prior local access with low-privileged code execution, which limits the attack surface compared to remote vulnerabilities.

Mitigation and workarounds

The vendor has released a fix in NoMachine version 9.4.14; all users should upgrade immediately (ZDI Advisory). The official NoMachine security bulletin is available at https://kb.nomachine.com/SU03X00271. As an interim measure, restrict local code execution access on systems running NoMachine to only trusted users, minimizing the pool of potential attackers who could satisfy the exploitation precondition.

Community reactions

The vulnerability was credited to an anonymous researcher through the Zero Day Initiative bug bounty program and disclosed following a coordinated timeline (ZDI Advisory). Brief social media mentions appeared on Bluesky and Mastodon shortly after the NVD publication on April 11, 2026, but no significant community debate or vendor controversy has been noted. Overall industry reaction has been muted, consistent with the low EPSS score and absence of active exploitation.

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management