← Back to search

CVE-2026-94382

4.2 MEDIUMpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The vulnerability allows any authenticated user to create or delete alerts on systems they shouldn't have access to, potentially disclosing sensitive information.
Exploitability
Exploitation requires an authenticated session but can be complex due to needing correct system IDs.
Blast radius
If exploited, it could lead to unauthorized access and disclosure of target system names and metrics.
Prioritized remediation
Update to Beszel version 0.19.0 or later to address the vulnerability.
auth-bypassapi-vulninfo-disclosure

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access. Attackers can supply arbitrary system IDs in the request body to register alert rules and receive notifications disclosing target system names and metrics.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Weaknesses

CWE-639

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.