PT-2026-99714 · Unknown · Nezha Dashboard

·

CVE-2026-101086

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nezha Dashboard versions prior to 2.3.5
Description Authenticated users with nezha:service:write scope can submit privileged task types through the service API because the system fails to restrict service monitor task types to supported probe types. By exploiting the shared protobuf Task.Type namespace between service monitors and privileged operations, attackers can deliver command execution or Agent configuration tasks to Agents within their authorization scope.
Recommendations Update to version 2.3.5 or later.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101086
GHSA-GRRW-FX36-FV32

Affected Products

Nezha Dashboard