Unknown · Nezha Dashboard · CVE-2026-101086
**Name of the Vulnerable Software and Affected Versions**
Nezha Dashboard versions prior to 2.3.5
**Description**
Authenticated users with `nezha:service:write` scope can submit privileged task types through the service API because the system fails to restrict service monitor task types to supported probe types. By exploiting the shared protobuf `Task.Type` namespace between service monitors and privileged operations, attackers can deliver command execution or Agent configuration tasks to Agents within their authorization scope.
**Recommendations**
Update to version 2.3.5 or later.