CVE-2026-101086
Received Received - Intake

Nezha Dashboard Unauthorized Privileged Task Execution

Vulnerability report for CVE-2026-101086, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. Attackers can deliver command execution or Agent configuration tasks to Agents within their authorization scope by exploiting the shared protobuf Task.Type namespace between service monitors and privileged operations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nezha dashboard to 2.3.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Nezha Dashboard versions before 2.3.5 do not properly restrict service monitor task types to only supported probe types. This flaw allows authenticated users with nezha:service:write scope to submit privileged task types via the service API. Attackers exploit the shared protobuf Task.Type namespace between service monitors and privileged operations to deliver malicious tasks like command execution or Agent configuration changes to authorized Agents.

Detection Guidance

Check Nezha Dashboard versions before 2.3.5 for unauthorized service monitor tasks. Review API logs for task types outside supported probe types. Look for unexpected command execution or Agent configuration tasks in the nezha:service:write scope.

Impact Analysis

If you use Nezha Dashboard before version 2.3.5, an attacker with valid credentials and the nezha:service:write scope could execute arbitrary commands or modify Agent configurations within their authorized scope. This could lead to unauthorized access, data theft, or system compromise depending on the Agent's permissions.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access or data exfiltration, which are common violations under GDPR (data protection) and HIPAA (health data security). Organizations using affected versions may face regulatory penalties or audit failures due to insufficient access controls.

Mitigation Strategies

Upgrade Nezha Dashboard to version 2.3.5 or later. Restrict nezha:service:write scope to authorized users only. Audit and remove any unauthorized service monitor tasks. Monitor for suspicious Agent configurations or command executions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101086. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart