PT-2026-79458 · Unknown · Nezha Monitoring

CVE-2026-62283

·

Published

2026-06-26

·

Updated

2026-08-22

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nezha Monitoring versions 1.14.13 through 1.14.14 Nezha Monitoring versions 2.0.0 through 2.0.9
Description Nezha Monitoring fails to bind stream identifiers created by the CreateStream function in service/rpc/io stream.go to the user who created them. Consequently, the endpoints 'GET /ws/terminal/:id' and 'GET /ws/file/:id' only verify the existence of the supplied UUID without enforcing user ownership or authorization. An authenticated RoleMember who obtains a live stream UUID through logs, browser history, referer data, or telemetry can hijack another user's terminal or file-manager session. This allows the attacker to read and write files on the target server and execute arbitrary shell commands.
Recommendations Update Nezha Monitoring versions 1.14.13 through 1.14.14 to version 2.0.10. Update Nezha Monitoring versions 2.0.0 through 2.0.9 to version 2.0.10.

Exploit

Fix

Missing Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62283
GHSA-Q6XX-5VR8-P898
GO-2026-5821

Affected Products

Nezha Monitoring