{"id":"CVE-2026-94382","published":"2026-09-21T14:17:30.170","lastModified":"2026-09-21T15:17:39.290","description":"Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access. Attackers can supply arbitrary system IDs in the request body to register alert rules and receive notifications disclosing target system names and metrics.","cvssScore":4.2,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://github.com/henrygd/beszel","tags":[]},{"url":"https://github.com/henrygd/beszel/blob/v0.18.8/internal/alerts/alerts_api.go#L19-L80","tags":[]},{"url":"https://github.com/henrygd/beszel/commit/6f92b9396dfbacaf71c20444d175af78e0517409","tags":[]},{"url":"https://github.com/henrygd/beszel/releases/tag/v0.19.0","tags":[]},{"url":"https://github.com/henrygd/beszel/security/advisories/GHSA-759g-ch5m-2gch","tags":[]},{"url":"https://www.vulncheck.com/advisories/beszel-before-0.19.0-insecure-direct-object-reference-via-user-alerts","tags":[]},{"url":"https://github.com/henrygd/beszel/security/advisories/GHSA-759g-ch5m-2gch","tags":[]}],"exploitRefs":[{"url":"https://github.com/henrygd/beszel","tags":[]},{"url":"https://github.com/henrygd/beszel/blob/v0.18.8/internal/alerts/alerts_api.go#L19-L80","tags":[]},{"url":"https://github.com/henrygd/beszel/commit/6f92b9396dfbacaf71c20444d175af78e0517409","tags":[]},{"url":"https://github.com/henrygd/beszel/releases/tag/v0.19.0","tags":[]},{"url":"https://github.com/henrygd/beszel/security/advisories/GHSA-759g-ch5m-2gch","tags":[]},{"url":"https://github.com/henrygd/beszel/security/advisories/GHSA-759g-ch5m-2gch","tags":[]}],"hasPoc":true,"ai":{"summary":"The vulnerability allows any authenticated user to create or delete alerts on systems they shouldn't have access to, potentially disclosing sensitive information.","exploitability":"Exploitation requires an authenticated session but can be complex due to needing correct system IDs.","blast_radius":"If exploited, it could lead to unauthorized access and disclosure of target system names and metrics.","remediation":"Update to Beszel version 0.19.0 or later to address the vulnerability.","tags":["auth-bypass","api-vuln","info-disclosure"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:34:43.808Z"}}