CVE-2026-83602
Publication date 22 September 2026
Last updated 24 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled by src/web/api/v3/api_v3_settings.c to bypass operator-configured allow dashboard from IP restrictions. A network-reachable caller can persist attacker-controlled JSON in {varlib}/settings/default.json, manipulate its version counter, and use repeated near-20 MiB writes to consume disk space, although the file does not control collection or security policy. This vulnerability is fixed in 2.11.0.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| netdata | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
6.5 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-83602
- https://github.com/netdata/netdata/commit/0124f50bbcf36c23e798e2b76f021f5032ec93d4
- https://github.com/netdata/netdata/pull/22896
- https://github.com/netdata/netdata/releases/tag/v2.11.0
- https://github.com/netdata/netdata/security/advisories/GHSA-8hjg-8hcf-fmwp