CVE-2026-101089
Received Received - Intake

Nezha Information Disclosure via Unprotected Profile Endpoint

Vulnerability report for CVE-2026-101089, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract password hashes and perform offline cracking attacks without rate limiting or audit trail constraints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Nezha before version 2.2.7 has an information disclosure vulnerability in the GET /api/v1/profile endpoint. This endpoint returns the bcrypt-hashed password field of authenticated users, allowing attackers to extract password hashes and perform offline cracking attempts without rate limiting or audit trail constraints.

Detection Guidance

To detect this vulnerability, check if your Nezha instance is running a version before 2.2.7. Inspect network traffic for requests to the GET /api/v1/profile endpoint. Verify if the response includes a bcrypt-hashed password field for authenticated users.

Impact Analysis

Attackers could obtain bcrypt-hashed passwords from the vulnerable endpoint and attempt to crack them offline. This could lead to unauthorized account access if weak or common passwords are used. The lack of rate limiting or audit trails may make detection of such attacks difficult.

Compliance Impact

This vulnerability could violate data protection requirements under GDPR and HIPAA by exposing sensitive user credentials. GDPR requires protection of personal data, while HIPAA mandates safeguards for protected health information. The disclosure of password hashes may indicate insufficient security controls.

Mitigation Strategies

Immediately upgrade Nezha to version 2.2.7 or later. If upgrading is not possible, restrict access to the /api/v1/profile endpoint and monitor for unauthorized access attempts. Rotate all bcrypt-hashed passwords if they may have been exposed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101089. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart