PT-2026-98221 · Dozzle · Dozzle

CVE-2026-62286

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dozzle versions prior to 10.6.7
Description In simple-auth deployments using per-user filters, the streamEvents function in internal/web/events.go fails to apply label filters to the container-stat and container-event channels returned by the 'GET /api/events/stream' endpoint. This allows authenticated restricted accounts to receive resource telemetry and lifecycle events for containers outside their authorized label scope. Exposed data includes container names, images, full label maps, CPU and memory usage, network and disk totals, and deployment or restart activity across monitored hosts. This does not include log contents, environment values, or exec access.
Recommendations Update to version 10.6.7.

Exploit

Fix

Improper Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62286
GHSA-XCW9-QMMF-VQXJ

Affected Products

Dozzle