CVE-2024-32019
Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of the Netdata Agent allows an attacker to run arbitrary programs with root permissions. The `ndsudo` tool is packaged as a `root`-owned executable with the SUID bit set. It only runs a restricted set of external commands, but its search paths are supplied by the `PATH` environment variable. This allows an attacker to control where `ndsudo` looks for these commands, which may be a path the attacker has write access to. This may lead to local privilege escalation. This vulnerability has been addressed in versions 1.45.3 and 1.45.2-169. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 1.17%
- CWE
- CWE-426
- Published
- 2024-04-12
- Last modified
- 2026-03-13
Affected products
- netdata netdata
- netdata netdata
Weakness type
Related vulnerabilities
- CVE-2026-0307 — GlobalProtect App: Local Privilege Escalation Vulnerabilities
- CVE-2026-80159 — Acrobat Reader | Untrusted Search Path (CWE-426)
- CVE-2026-81192 — OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
- CVE-2026-78574 — Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling
- CVE-2026-69785 — Windows Smart Card Elevation of Privilege Vulnerability
- CVE-2026-69328 — Windows Storage Elevation of Privilege Vulnerability
- CVE-2026-84226 — OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local...
- CVE-2026-82862 — Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files