---
cve: "CVE-2026-83602"
severity: "MEDIUM"
cvss: 6.5
epss: "0.5%"
vendor: "netdata"
kev: false
exploited: false
published: "2026-09-22 17:17:26"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-29T07:41:56+02:00"
---

# CVE-2026-83602

> 6.5 MEDIUM · 🧪 PoC

## Beschreibung

Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled by src/web/api/v3/api_v3_settings.c to bypass operator-configured allow dashboard from IP restrictions. A network-reachable caller can persist attacker-controlled JSON in {varlib}/settings/default.json, manipulate its version counter, and use repeated near-20 MiB writes to consume disk space, although the file does not control collection or security policy. This vulnerability is fixed in 2.11.0.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Gering | warn |

## Patch verfügbar (OSV)

- 0124f50bbcf36c23e798e2b76f021f5032ec93d4 (Commit)
- bb8f509e99cad230d3acc1fdfc840224f3b3db3a (Commit)

## Referenzen

- <https://github.com/netdata/netdata/security/advisories/GHSA-8hjg-8hcf-fmwp>
- <https://github.com/netdata/netdata/pull/22896>
- <https://github.com/netdata/netdata/commit/0124f50bbcf36c23e798e2b76f021f5032ec93d4>
- <https://github.com/netdata/netdata/releases/tag/v2.11.0>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-83602) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
