← Vulnerability feed

Vulnerability record · CVE-2023-39107 · published 4 August 2023

CVE-2023-39107: Nomachine link following vulnerability

Nomachine · Nomachine

An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-owned files by using hardlinks.

9.1 CVSS 3.1 Critical EPSS 1.2% · top 32.6% CWE-59 · Link following
9.1CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-owned files by using hardlinks.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-39107 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0664Nomachine improper input validation vulnerabilityA vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unspecified vectors.EPSS 1.7%8.8CVE-2017-12763Nomachine incorrect default permissions vulnerabilityAn unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to loc…EPSS 3.9%7.8CVE-2026-5055Nomachine uncontrolled search path element vulnerabilityNoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges…EPSS 0.20%7.8CVE-2026-5054Nomachine vulnerabilityNoMachine External Control of File Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on…EPSS 0.17%7.8CVE-2025-8614Nomachine uncontrolled search path element vulnerabilityNoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges…EPSS 0.27%7.8CVE-2024-7253Nomachine uncontrolled search path element vulnerabilityNoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges…EPSS 0.35%7.8CVE-2018-17980Nomachine untrusted search path vulnerabilityNoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same directory a…EPSS 4.6%7.8CVE-2018-6947Nomachine vulnerabilityAn uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier a…EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2023-39107), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.