Junglewise Threat Intelligence

CVE-2026-94382: Beszel insecure direct object reference in user alerts API

CVE-2026-94382 · Severity: medium · CVSS 4.2 · Published 2026-09-21

Executive brief

Beszel is a lightweight server monitoring system that collects metrics and sends alerts. Attackers who log in as any user can manipulate alert rules for systems they should not have access to, allowing them to create fake alerts, delete legitimate ones, and potentially see system names and performance metrics they are not authorized to view.

Technical details

An insecure direct object reference (IDOR) in the POST and DELETE /api/beszel/user-alerts handlers allows authenticated users to supply arbitrary system IDs in the request body without authorization checks. The vulnerability affects the alert management logic, permitting attackers to create or delete alert rules on systems outside their access scope and receive disclosures of target system names and metrics. The fix was released in version 0.19.0.

Affected products

  • henrygd Beszel before 0.19.0

Timeline

  • 2026-09-21: disclosed

References

Related threats