<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 14:03:00 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-327390</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-327390</link>
      <description>EUVD-2026-327390</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-327390</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46716</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46716</link>
      <description>&lt;p&gt;Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&amp;amp;M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Command. At every tick of the scheduler, the dashboard pushes that command to every server in the global ServerShared map — including servers that belong to other tenants (admin&amp;#39;s servers, other members&amp;#39; servers). Each agent runs the command and returns the output, which is then sent to the attacker&amp;#39;s own NotificationGroup → attacker-controlled webhook. This issue has been patched in version 2.0.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&amp;amp;M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Command. At every tick of the scheduler, the dashboard pushes that command to every server in the global ServerShared map — including servers that belong to other tenants (admin&amp;#39;s servers, other members&amp;#39; servers). Each agent runs the command and returns the output, which is then sent to the attacker&amp;#39;s own NotificationGroup → attacker-controlled webhook. This issue has been patched in version 2.0.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46716</guid>
    </item>
    <item>
      <title>GHSA-99gv-2m7h-3hh9 — Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-99gv-2m7h-3hh9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/nezhahq/nezha&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`nezha`&amp;#39;s dashboard supports two user roles: `RoleAdmin` (Role==0) and `RoleMember` (Role==1). The cron routes `POST /api/v1/cron` and `PATCH /api/v1/cron/:id` are wired through `commonHandler` (any authenticated user) rather than `adminHandler`, and the per-server permission check on cron creation has a vacuous-true bypass.&lt;/p&gt;
&lt;p&gt;A `RoleMember` user can create a scheduled cron task with `Cover=CronCoverAll, Servers=[]` and an arbitrary `Command`. At every tick of the scheduler, the dashboard pushes that command to **every server in the global `ServerShared` map** — including servers that belong to other tenants (admin&amp;#39;s servers, other members&amp;#39; servers). Each agent runs the command and returns the output, which is then sent to the attacker&amp;#39;s own NotificationGroup → attacker-controlled webhook.&lt;/p&gt;
&lt;p&gt;Net effect: any `RoleMember` (including a self-bound OAuth2 user, if the dashboard has OAuth2 configured) gets pre-validated cross-tenant RCE on every nezha-monitored host in the deployment.&lt;/p&gt;
&lt;p&gt;## Affected versions&lt;/p&gt;
&lt;p&gt;Commit `50dc8e660326b9f22990898142c58b7a5312b42a` and earlier on `master`.&lt;/p&gt;
&lt;p&gt;## The auth gate&lt;/p&gt;
&lt;p&gt;```go
// cmd/dashboard/controller/controller.go:131-135
auth.GET(&amp;#34;/cron&amp;#34;, listHandler(listCron))
auth.POST(&amp;#34;/cron&amp;#34;, commonHandler(createCron))                    // &amp;lt;-- commonHandler, not adminHandler
auth.PATCH(&amp;#34;/cron/:id&amp;#34;, commonHandler(updateCron))               // &amp;lt;-- ditto
auth.GET(&amp;#34;/cron/:id/manual&amp;#34;, commonHandler(manualTriggerCron))
auth.POST(&amp;#34;/batch-delete/cron&amp;#34;, comm…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/nezhahq/nezha&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`nezha`&amp;#39;s dashboard supports two user roles: `RoleAdmin` (Role==0) and `RoleMember` (Role==1). The cron routes `POST /api/v1/cron` and `PATCH /api/v1/cron/:id` are wired through `commonHandler` (any authenticated user) rather than `adminHandler`, and the per-server permission check on cron creation has a vacuous-true bypass.&lt;/p&gt;
&lt;p&gt;A `RoleMember` user can create a scheduled cron task with `Cover=CronCoverAll, Servers=[]` and an arbitrary `Command`. At every tick of the scheduler, the dashboard pushes that command to **every server in the global `ServerShared` map** — including servers that belong to other tenants (admin&amp;#39;s servers, other members&amp;#39; servers). Each agent runs the command and returns the output, which is then sent to the attacker&amp;#39;s own NotificationGroup → attacker-controlled webhook.&lt;/p&gt;
&lt;p&gt;Net effect: any `RoleMember` (including a self-bound OAuth2 user, if the dashboard has OAuth2 configured) gets pre-validated cross-tenant RCE on every nezha-monitored host in the deployment.&lt;/p&gt;
&lt;p&gt;## Affected versions&lt;/p&gt;
&lt;p&gt;Commit `50dc8e660326b9f22990898142c58b7a5312b42a` and earlier on `master`.&lt;/p&gt;
&lt;p&gt;## The auth gate&lt;/p&gt;
&lt;p&gt;```go
// cmd/dashboard/controller/controller.go:131-135
auth.GET(&amp;#34;/cron&amp;#34;, listHandler(listCron))
auth.POST(&amp;#34;/cron&amp;#34;, commonHandler(createCron))                    // &amp;lt;-- commonHandler, not adminHandler
auth.PATCH(&amp;#34;/cron/:id&amp;#34;, commonHandler(updateCron))               // &amp;lt;-- ditto
auth.GET(&amp;#34;/cron/:id/manual&amp;#34;, commonHandler(manualTriggerCron))
auth.POST(&amp;#34;/batch-delete/cron&amp;#34;, comm…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-99gv-2m7h-3hh9</guid>
    </item>
  </channel>
</rss>
