Junglewise Threat Intelligence

CVE-2026-40077: Henrygd Beszel IDOR in hub API endpoints

CVE-2026-40077 · Severity: low · CVSS 3.5 · Published 2026-04-10

Vendors: Go.

Executive brief

Beszel, a lightweight server monitoring dashboard, contains a security flaw where authenticated users can access data from servers they are not authorized to view. By knowing or guessing a specific server ID, a user could view container logs, system service information, or trigger hardware health checks on systems belonging to other users. This could lead to the exposure of sensitive application logs or operational data.

Technical details

An Insecure Direct Object Reference (IDOR) exists in the Beszel hub's custom API endpoints within `internal/hub/api.go`. The `containerRequestHandler`, `getSystemdInfo`, and `refreshSmartData` functions retrieve system objects using a user-provided `systemID` from URL parameters but fail to verify if the authenticated user (`e.Auth.Id`) has permission to access that specific system. While system IDs are 15-character random alphanumeric strings, they can potentially be enumerated. An attacker with any valid account can exploit this to retrieve container logs, container metadata, systemd service status, or trigger SMART data refreshes on unauthorized systems. The issue is fixed in version 0.18.7 by implementing proper membership checks.

Affected products

  • henrygd Beszel <= 0.18.6

Timeline

  • 2026-04-09: disclosed
  • 2026-04-10: advisory
  • 2026-04-10: patched: Fixed in version 0.18.7

References

Related threats