Cross-Site Request Vulnerability in Nezha Monitoring Tool by Nezha HQ
CVE-2026-49396
7.1HIGH
What is CVE-2026-49396?
The Nezha Monitoring tool, which serves as a lightweight solution for monitoring servers and websites, is susceptible to a cross-site request vulnerability that allows attackers to execute stored cron commands on a victim's agent. This vulnerability affects versions 1.0.0 through prior to 2.0.14. Users are encouraged to upgrade to version 2.0.14 or later, where this issue has been effectively resolved.
Affected Version(s)
nezha >= 1.0.0, < 2.0.14
