Arbitrary Command Execution in Nezha Monitoring by NezhaHQ
CVE-2026-46716
9.9CRITICAL
What is CVE-2026-46716?
Nezha Monitoring, a self-hostable monitoring tool, is susceptible to an arbitrary command execution vulnerability. Users with RoleMember permissions can create scheduled cron tasks that execute arbitrary commands on any server registered in the ServerShared map, including those belonging to other tenants. This security flaw allows an attacker to push harmful commands to servers of other users and collect the output through a webhook under their control, risking unauthorized access to sensitive data and server operations. The issue has been remedied in version 2.0.8.
Affected Version(s)
nezha >= 1.4.0, < 2.0.8
