Role Escalation Vulnerability in Nezha Monitoring by NezhaHQ
CVE-2026-47120

7.1HIGH

Key Information:

Vendor

Nezhahq

Status
Vendor
CVE Published:
12 June 2026

What is CVE-2026-47120?

Nezha Monitoring, a self-hostable tool for monitoring servers and websites, has a role escalation vulnerability affecting versions 1.4.0 through 2.0.7. Users with the RoleMember privilege can improperly trigger cron tasks belonging to other users due to the absence of ownership validation in the AlertRule's FailTriggerTasks functionality. This issue was resolved in version 2.0.8, which introduced necessary checks to prevent unauthorized access and protect user data.

Affected Version(s)

nezha >= 1.4.0, < 2.0.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.