OVERVIEW CVE-2026-5055 is an uncontrolled search path element vulnerability affecting NoMachine's Device Server component. The flaw allows local attackers with low-privilege code execution capabilities to escalate their privileges by exploiting an insecure library loading mechanism, ultimately achieving SYSTEM-level access and arbitrary code execution on vulnerable systems. SEVERITY This vulnerability carries a CVSS 3.0 score of 7.8 (HIGH), reflecting a local attack vector with low complexity and no user interaction required. The attack requires prior low-privilege code execution on the target system. Successfully exploiting this flaw grants the attacker complete system compromise with high confidentiality, integrity, and availability impact through SYSTEM-level code execution capabilities. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog, and community attention remains minimal as indicated by its inactive Hot List status. The EPSS score of 0.00016 suggests substantially lower exploitation probability compared to the CVE baseline, indicating this remains a theoretical risk at present with no publicly available proof-of-concept exploit actively circulating.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.4.14CPE matchmatch criteria | cpe:2.3:a:nomachine:nomachine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.