CVE-2026-94382

Source
https://cve.org/CVERecord?id=CVE-2026-94382
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94382.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-94382
Aliases
  • GHSA-759g-ch5m-2gch
Published
2026-09-21T12:59:39Z
Modified
2026-09-25T03:31:12Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Beszel before 0.19.0 Insecure Direct Object Reference via user-alerts
Details

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access. Attackers can supply arbitrary system IDs in the request body to register alert rules and receive notifications disclosing target system names and metrics.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-639"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94382.json"
}
References

Affected packages

Git / github.com/henrygd/beszel

Affected ranges

Type
GIT
Repo
https://github.com/henrygd/beszel
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.19.0"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

beszel-agent-v0.*
beszel-agent-v0.1.1
beszel-agent-v0.1.2
beszel-agent-v0.1.3
beszel-agent-v0.1.4
beszel-hub-v0.*
beszel-hub-v0.1.1
beszel-hub-v0.1.2
beszel-hub-v0.1.3
beszel-hub-v0.1.4
v0.*
v0.0.1
v0.0.1-alpha.0
v0.0.1-alpha.1
v0.0.1-alpha.2
v0.0.1-alpha.3
v0.0.1-alpha.4
v0.0.1-alpha.5
v0.0.1-alpha.6
v0.0.1-alpha.7
v0.0.1-alpha.8
v0.0.1-alpha.9
v0.1.0
v0.1.1
v0.1.2
v0.10.0
v0.10.1
v0.10.2
v0.11.0
v0.11.1
v0.12.0
v0.12.0-beta1
v0.12.0-beta2
v0.12.1
v0.12.10
v0.12.11
v0.12.12
v0.12.2
v0.12.3
v0.12.4
v0.12.5
v0.12.6
v0.12.7
v0.12.8
v0.12.9
v0.13.0
v0.13.1
v0.13.2
v0.14.0
v0.14.1
v0.15.0
v0.15.1
v0.15.2
v0.15.3
v0.15.4
v0.16.0
v0.16.1
v0.17.0
v0.18.0
v0.18.1
v0.18.2
v0.18.3
v0.18.4
v0.18.5
v0.18.6
v0.18.7
v0.18.8
v0.2.0
v0.3.0
v0.4.0
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.8.0
v0.9.0
v0.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94382.json"