Role Escalation Vulnerability in Nezha Monitoring by NezhaHQ
CVE-2026-47120
7.1HIGH
What is CVE-2026-47120?
Nezha Monitoring, a self-hostable tool for monitoring servers and websites, has a role escalation vulnerability affecting versions 1.4.0 through 2.0.7. Users with the RoleMember privilege can improperly trigger cron tasks belonging to other users due to the absence of ownership validation in the AlertRule's FailTriggerTasks functionality. This issue was resolved in version 2.0.8, which introduced necessary checks to prevent unauthorized access and protect user data.
Affected Version(s)
nezha >= 1.4.0, < 2.0.8
