Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata service account. The account can direct root fail2ban-client to a malicious UNIX socket, and fail2ban/client/csocket.py CSocket.receive() passes the returned data to pickle.loads(), allowing attacker-controlled code to execute as root on systems with fail2ban-client installed. This issue is fixed in version 2.10.4 and nightly build 2.10.0-782-nightly.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-502",
"CWE-73"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83603.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-83603.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"145502671235432794023844567434327174601",
"304372119545992816617684381727583601007",
"73450841204797344488191033477509041071",
"197961079879052031371221752648773688265",
"70713990567942265007864732196086641108",
"22828932509653172035916910630643388984",
"6267422522785001239350338372685845854",
"183648796998145560939801182552564360690",
"307918585819356045600218673644898913427",
"101354288147399063875143168779890117314",
"273237870677431648392506380041709126428"
],
"threshold": 0.9
},
"id": "CVE-2026-83603-319ac665",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/netdata/netdata/commit/9bced8d46464bd0fe01b0b5f8c63c4ac24e9b060",
"target": {
"file": "src/collectors/utils/ndsudo.c"
}
}
]
"2026-09-25T08:24:15Z"