PT-2026-79458 · Unknown · Nezha Monitoring
CVE-2026-62283
·
Published
2026-06-26
·
Updated
2026-08-22
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nezha Monitoring versions 1.14.13 through 1.14.14
Nezha Monitoring versions 2.0.0 through 2.0.9
Description
Nezha Monitoring fails to bind stream identifiers created by the
CreateStream function in service/rpc/io stream.go to the user who created them. Consequently, the endpoints 'GET /ws/terminal/:id' and 'GET /ws/file/:id' only verify the existence of the supplied UUID without enforcing user ownership or authorization. An authenticated RoleMember who obtains a live stream UUID through logs, browser history, referer data, or telemetry can hijack another user's terminal or file-manager session. This allows the attacker to read and write files on the target server and execute arbitrary shell commands.Recommendations
Update Nezha Monitoring versions 1.14.13 through 1.14.14 to version 2.0.10.
Update Nezha Monitoring versions 2.0.0 through 2.0.9 to version 2.0.10.
Exploit
Fix
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nezha Monitoring