Arbitrary Command Execution in Nezha Monitoring by NezhaHQ
CVE-2026-46716

9.9CRITICAL

Key Information:

Vendor

Nezhahq

Status
Vendor
CVE Published:
12 June 2026

What is CVE-2026-46716?

Nezha Monitoring, a self-hostable monitoring tool, is susceptible to an arbitrary command execution vulnerability. Users with RoleMember permissions can create scheduled cron tasks that execute arbitrary commands on any server registered in the ServerShared map, including those belonging to other tenants. This security flaw allows an attacker to push harmful commands to servers of other users and collect the output through a webhook under their control, risking unauthorized access to sensitive data and server operations. The issue has been remedied in version 2.0.8.

Affected Version(s)

nezha >= 1.4.0, < 2.0.8

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.