---
id: CVE-2026-101086
title: >-
  Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task
  types to supported probe types, allowing authenticated users with
  nezha:service:write scope to submit privileged task types through the service
  API
summary: >-
  Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task
  types to supported probe types, allowing authenticated users with
  nezha:service:write scope to submit privileged task types through the service
  API. Attackers ca…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-269
vendor: nezhahq
product: nezha
affected:
  - nezha < 2.3.5
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T21:17:02.450'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101086'
references:
  - url: >-
      https://github.com/nezhahq/nezha/commit/38824dbc11a63964c5b9296ae4c68e62b34fa04b
    label: disclosure@vulncheck.com
  - url: 'https://github.com/nezhahq/nezha/security/advisories/GHSA-grrw-fx36-fv32'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nezha-dashboard-before-2.3.5-task-type-validation-bypass
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T20:58:01.541Z'
---

## Overview

Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. Attackers can deliver command execution or Agent configuration tasks to Agents within their authorization scope by exploiting the shared protobuf Task.Type namespace between service monitors and privileged operations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
