Insecure Direct Object Reference in Beszel API by Vendor Henrygd
CVE-2026-94382

2.3LOW

Key Information:

Vendor

Henrygd

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-94382?

The Beszel application prior to version 0.19.0 exhibits an insecure direct object reference vulnerability involving its /api/beszel/user-alerts endpoints. Authenticated users can exploit this flaw to manipulate alerts, allowing them to create or delete alerts against system IDs that they shouldn't have access to. This could lead to unauthorized notifications disclosing sensitive system information, such as names and metrics. It is crucial for users to update their Beszel installations to the latest version to mitigate this security risk.

Affected Version(s)

beszel 0 < 0.19.0

beszel 0.19.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Onetatcode
DeathXcorE
DavidCarliez
ka3n1x
.