SecBoard
Zurück zur CVE-Übersicht

CVE-2026-47120

HIGH(7.1)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Risk Signal Score23/100 — NIEDRIG
  • CVSS 7.1 — Hoch

EPSS-Score

0%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

7.1

Technische Schwere

Beschreibung

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check). This issue has been patched in version 2.0.8.

GitHub Advisories

GHSA-rxf6-wjh4-jfj6MEDIUM

Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)

go/github.com/nezhahq/nezha1.14.15-0.20260517022419-d7526351cf97
GitHub Advisory

Referenzen