Executive brief
Beszel, a lightweight server monitoring dashboard, contains a security flaw where authenticated users can access data from servers they are not authorized to view. By knowing or guessing a specific server ID, a user could view container logs, system service information, or trigger hardware health checks on systems belonging to other users. This could lead to the exposure of sensitive application logs or operational data.
Technical details
An Insecure Direct Object Reference (IDOR) exists in the Beszel hub's custom API endpoints within `internal/hub/api.go`. The `containerRequestHandler`, `getSystemdInfo`, and `refreshSmartData` functions retrieve system objects using a user-provided `systemID` from URL parameters but fail to verify if the authenticated user (`e.Auth.Id`) has permission to access that specific system. While system IDs are 15-character random alphanumeric strings, they can potentially be enumerated. An attacker with any valid account can exploit this to retrieve container logs, container metadata, systemd service status, or trigger SMART data refreshes on unauthorized systems. The issue is fixed in version 0.18.7 by implementing proper membership checks.
Affected products
- henrygd Beszel <= 0.18.6
Timeline
- 2026-04-09: disclosed
- 2026-04-10: advisory
- 2026-04-10: patched: Fixed in version 0.18.7