NetBird released v0.76.0 to fix a high-severity local privilege escalation flaw in its client daemon, tracked as GHSA-qcpp-8vwj-hhwr and rated CVSS 8.8. The vulnerability affected all client versions from v0.5.0 through v0.75.1 on Linux, macOS, FreeBSD, and Windows because the daemon’s local gRPC control interface accepted privileged commands from any local process without authentication. On Unix-like systems, the daemon exposed a world-readable and world-writable Unix socket; on Windows, it listened on an unauthenticated loopback TCP port at 127.0.0.1:41731. NetBird said the issue was not remotely exploitable, did not affect its management server, signal server, relays, or NetBird Cloud, and that it has no evidence of in-the-wild exploitation.
A local attacker could read configuration, change security-sensitive settings, disconnect the VPN, deregister a peer, and re-register the device to an attacker-controlled NetBird account; in some deployments, the flaw could also be chained with NetBird SSH to obtain a root shell. The fix, merged through pull request #6967, adds OS-level caller identity verification using kernel-derived local credentials and restricts dangerous operations such as changing the management URL, deregistering peers, and weakening SSH protections to privileged users only. NetBird said there is no safe workaround that preserves the exposed socket, making an upgrade to v0.76.0 the required remediation for affected clients.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
NetBird released version 0.76.0 as the remediation for the local privilege escalation vulnerability affecting client versions 0.5.0 through 0.75.1. The fix added OS-level caller identity checks and restricted dangerous operations such as enabling SSH root login, changing the management URL, and deregistering peers to privileged users only.
NetBird merged pull request #6967 into main, integrating code to derive caller identity from the operating system and enforce privilege checks around sensitive daemon operations. The merged change also included the Windows move away from the unauthenticated loopback TCP listener toward named pipes.
NetBird said the flaw had existed since version 0.5.0, when the client architecture exposed a local gRPC daemon interface that did not authenticate local callers. This established the start of the affected version range later identified as 0.5.0 through 0.75.1.
NetBird publicly disclosed the high-severity local privilege escalation issue in advisory GHSA-qcpp-8vwj-hhwr, describing how any local process could issue privileged daemon RPCs without authentication on Linux, macOS, FreeBSD, and Windows. NetBird stated the issue was not remotely exploitable, did not affect NetBird Cloud or server-side components, and that it had no evidence of exploitation in the wild.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
netbird.io
Open sourcenetbird.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.