← Späť na vyhľadávanie CVE

CVE-2026-40077

Beszel

Popis

Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied system ID and proceed without further checks that the user should have access to that system. As a result, any authenticated user can access these routes for any system if they know the system-s ID. System IDs are random 15 character alphanumeric strings, and are not exposed to all users. However, it is theoretically possible for an authenticated user to enumerate a valid system ID via web API. To use the containers endpoints, the user would also need to enumerate a container ID, which is 12 digit hexadecimal string. This vulnerability is fixed in 0.18.7.

CVSS 3.5EPSS 0.219%Riziko 0.36
Zobraziť zdroj
Zverejnené
2026-04-09 20:16:27
Dotknuté verzie
<0.18.7
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N