PT-2026-98221 · Dozzle · Dozzle
CVE-2026-62286
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dozzle versions prior to 10.6.7
Description
In simple-auth deployments using per-user filters, the
streamEvents function in internal/web/events.go fails to apply label filters to the container-stat and container-event channels returned by the 'GET /api/events/stream' endpoint. This allows authenticated restricted accounts to receive resource telemetry and lifecycle events for containers outside their authorized label scope. Exposed data includes container names, images, full label maps, CPU and memory usage, network and disk totals, and deployment or restart activity across monitored hosts. This does not include log contents, environment values, or exec access.Recommendations
Update to version 10.6.7.
Exploit
Fix
Improper Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dozzle