CVE-2026-101086

Source
https://cve.org/CVERecord?id=CVE-2026-101086
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101086.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-101086
Aliases
  • GHSA-grrw-fx36-fv32
Published
2026-09-27T20:49:58Z
Modified
2026-09-29T03:45:58Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Nezha Dashboard before 2.3.5 Task Type Validation Bypass
Details

Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. Attackers can deliver command execution or Agent configuration tasks to Agents within their authorization scope by exploiting the shared protobuf Task.Type namespace between service monitors and privileged operations.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-269"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101086.json"
}
References

Affected packages

Git / github.com/nezhahq/nezha

Affected ranges

Type
GIT
Repo
https://github.com/nezhahq/nezha
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.3.5"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v2.*
v2.2.1
v2.2.10
v2.2.11
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.9
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101086.json"