Knowledge Base
Searching in : Trouble report
ID:TR06X11869
Added on: 2026-06-30
Last Update: 2026-07-30
Solved in version: 9.8.2 ; 8.26.1
Platform: All Platforms
Product: NoMachine Server
Severity: Serious
Status: Solved
Print this article

Possible escalation of privileges by impersonating the nx user (CVE-2026-18264)

The following problem has been reported by https://www.zerodayinitiative.com/advisories/ZDI-26-483/ and assigned with CVE-2026-1826.

A logged user could exploit the nx user via some server handlers to gain privileges for executing arbitrary operations.

This issue affected NoMachine v9 and v8. It is now fixed in v9.8.2 https://kb.nomachine.com/SU07X00280 and v8.26.1 https://kb.nomachine.com/SU07X00281.

SOLVED, Released in version 9.8.2 ; 8.26.1