QSearchQSearch

CVE-2026-47124

6.5 MEDIUM

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool

Published: 2026-06-12 · Last updated: 2026-06-12

Severity and scoring

CVSS
6.5 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE
CWE-200

Description

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.9, any authenticated non-admin member can connect to the server-status WebSocket and receive telemetry for all servers, including servers owned by other users. The normal server list API filters objects by HasPermission, but the WebSocket stream treats the presence of any authenticated user as authorization for the full unfiltered server list. This issue has been patched in version 2.0.9.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-49397 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool (5.3 MEDIUM)
  • CVE-2026-54396 An information disclosure vulnerability exists in the MISP AuthKey edit functionality
  • CVE-2026-47264 Discourse is an open-source discussion platform (5.3 MEDIUM)
  • CVE-2026-47263 Discourse is an open-source discussion platform (4.3 MEDIUM)
  • CVE-2026-45085 Discourse is an open-source discussion platform (5.3 MEDIUM)