PT-2026-48482 · Unknown · Nezha Monitoring

CVE-2026-49397

·

Published

2026-06-10

·

Updated

2026-07-30

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nezha Monitoring versions 2.0.0 through 2.0.13
Description Private services configured with EnableShowInService: false are enumerable, leading to the leak of service names and timing data. While the main service-listing endpoint correctly filters these services, other reader endpoints bypass this restriction. Unauthenticated visitors can enumerate hidden services by guessing public server IDs or service IDs.
Technical details include the following affected endpoints:
  • '/api/v1/server/:id/service' (via the listServerServices function)
  • '/api/v1/service/:id/history' (via the getServiceHistory function)
This issue allows unauthorized actors to disclose the existence and purpose of internal services and expose latency data, which can be used to infer business activity patterns and backend topology.
Recommendations Update to version 2.0.14.

Exploit

Fix

Incorrect Authorization

Improper Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49397
GHSA-VRMH-5MMX-HJWX
GO-2026-5672
OPENSUSE-SU-2026:21483-1

Affected Products

Nezha Monitoring