Sceawere

Vulnerability Detail

CVE-2026-101086UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Nezha Dashboard Arbitrary Task Execution

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
11h ago
Vendor
nezhahq
Product
nezha
Attack Type
Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. Attackers can deliver command execution or Agent configuration tasks to Agents within their authorization scope by exploiting the shared protobuf Task.Type namespace between service monitors and privileged operations.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-27T21:17:02.450Z",
  "pubdate": "2026-09-27T21:17:02.450Z",
  "executiveSummary": "Nezha Dashboard versions prior to 2.3.5 contain a critical vulnerability in the service monitor task validation logic, allowing authenticated users with 'nezha:service:write' scope to execute unauthorized privileged operations.\nThe vulnerability stems from the improper sanitization of task types within the service API, which utilizes a shared protobuf 'Task.Type' namespace for both routine service monitors and high-privilege administrative functions.\nAn authenticated attacker can abuse this design flaw to inject restricted commands or arbitrary Agent configuration tasks into target Agents. This allows the execution of arbitrary system commands or unauthorized re-configuration of the Agent's operational state.\nThe impact is significant, as it effectively grants command execution capabilities to low-privileged users, potentially leading to full control over affected Agents. Exploitation requires valid authentication with specific service-write privileges but does not necessitate further interaction from the target.\nRisk implications include full host compromise, lateral movement within the monitored infrastructure, and complete circumvention of intended authorization boundaries. Organizations using Nezha Dashboard are strongly advised to upgrade to version 2.3.5 or later to enforce strict input validation for task types.",
  "technicalDetails": "The root cause of the vulnerability lies in the insufficient input validation of the 'Task.Type' field within the Nezha Dashboard's service API. The application employs a shared protobuf namespace for defining tasks intended for Agent execution.\nWhile the intended design restricts service monitors to specific probe-related task types, the backend logic fails to verify whether a submitted task type is appropriate for the service monitor subsystem. Consequently, the API treats all 'Task.Type' inputs as valid, provided the user holds the 'nezha:service:write' scope.\nThe exploitation flow begins when an authenticated attacker interacts with the service API endpoint. By crafting a malformed request, the attacker specifies a 'Task.Type' associated with privileged administrative operations (such as command execution or Agent configuration) rather than a legitimate service monitoring probe.\nBecause the shared protobuf architecture does not implement server-side enforcement of task-type context, the dashboard dispatcher transmits the payload directly to the targeted Agent. The Agent, receiving a syntactically valid protobuf message, processes the instruction as if it originated from an authorized administrative session.\nThis allows the attacker to bypass the intended authorization constraints that differentiate between service monitoring tasks and system-level configuration or command execution tasks. The payload is executed on the target Agent with the same system privileges as the Agent process itself.\nVulnerable component: Nezha Dashboard API (Service Monitor handling). Affected versions: All versions prior to 2.3.5. Authentication is strictly required, specifically holding the 'nezha:service:write' privilege. No specific network exposure beyond the dashboard interface is required, as the vulnerability is logic-based and accessible via standard API interaction.\nPost-exploitation, the attacker gains the ability to execute arbitrary shell commands on any Agent within their authorized scope. This facilitates total system compromise, exfiltration of sensitive configuration data, or the deployment of persistent malicious agents within the monitored infrastructure."
}
CVE-2026-101086: Nezha Dashboard Arbitrary Task Execution (MEDIUM Severity, CVSS: 6.5) | Sceawere