CVE-2026-5053 HIGH

CVE-2026-5053: NoMachine External Control of File Path Arbitrary File Deletion Vulnerability

Vendor Nomachine
Product NoMachine
Weakness CWE-73
Published April 11, 2026
Last update April 13, 2026

CVSS base score

7.1/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

What the vulnerability does

01Description

NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability allows local attackers to delete arbitrary files on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of environment variables. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of root. Was ZDI-CAN-28644.

Key dates

02Disclosure timeline

April 11, 2026 CVE published
April 13, 2026 Record updated