CVE-2026-62283Critical· 9.9▾ MidnightNezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_strea…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_stream.go to their creating user, and GET /ws/terminal/:id and GET /ws/file/:id only check whether the supplied UUID exists. An authenticated RoleMember who obtains a live stream UUID from logs, browser history, referer data, or telemetry can attach to another user's terminal or file-manager session, read and write target-server files, and execute shell commands. This issue is fixed in version 2.0.10.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/nezhahq/nezha >= 1.14.13, <= 1.14.14github.com/nezhahq/nezha >= 2.0.0, < 2.0.10Patched in:
github.com/nezhahq/nezha 2.0.10Connected by shared product, vendor, weakness, or advisory.
GHSA-q6xx-5vr8-p898Critical· 9.9Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
GHSA-rf68-8gjr-36q7LowNezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
CVE-2026-48119High· 7.1Nezha's authenticated agents can forge service-monitor results for other users' services
CVE-2026-49396High· 7.1Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
CVE-2026-49397Medium· 5.3Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
CVE-2026-53520Medium· 6.5Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing