Unauthorized Access in Beszel Server Monitoring Platform
CVE-2026-40077
3.5LOW
What is CVE-2026-40077?
The Beszel Server Monitoring Platform contains a vulnerability that allows authenticated users to access API endpoints without appropriate permissions. Prior to version 0.18.7, certain API routes accepted a user-provided system ID, granting access to any system if the ID was known. Although system IDs are designed to be random alphanumeric strings, the possibility exists for users to enumerate valid IDs through the web API. To exploit this, attackers may also have to decipher a container ID, which is presented as a 12-digit hexadecimal string. This flaw has been addressed in the latest release, version 0.18.7, which implements further access control checks.
Affected Version(s)
beszel < 0.18.7
