Executive brief
Beszel is a lightweight server monitoring system that collects metrics and sends alerts. Attackers who log in as any user can manipulate alert rules for systems they should not have access to, allowing them to create fake alerts, delete legitimate ones, and potentially see system names and performance metrics they are not authorized to view.
Technical details
An insecure direct object reference (IDOR) in the POST and DELETE /api/beszel/user-alerts handlers allows authenticated users to supply arbitrary system IDs in the request body without authorization checks. The vulnerability affects the alert management logic, permitting attackers to create or delete alert rules on systems outside their access scope and receive disclosures of target system names and metrics. The fix was released in version 0.19.0.
Affected products
- henrygd Beszel before 0.19.0
Timeline
- 2026-09-21: disclosed