CVE-2026-53694: Potential local privileges escalation through argument injection in the nxchmod.sh script
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before 9.5.7, before 8.23.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nomachineto a version that resolves this vulnerability.Fixed in 9.5.7 - Upgrade
Upgrade
Nomachineto a version that resolves this vulnerability.Fixed in 8.23.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53694?
CVE-2026-53694 has a risk score of 44, indicating a moderate severity level for potential local privilege escalation.
How do I fix CVE-2026-53694?
To mitigate CVE-2026-53694, upgrade your NoMachine installation to version 9.5.7 or later, or version 8.23.2 or later.
What systems are affected by CVE-2026-53694?
CVE-2026-53694 affects NoMachine versions prior to 9.5.7 and 8.23.2.
What is the impact of CVE-2026-53694?
CVE-2026-53694 could lead to local privilege escalation through argument injection, allowing unauthorized command execution.
Is CVE-2026-53694 exploitable remotely?
CVE-2026-53694 is not a remote vulnerability; it requires local access to exploit.