CVE-2026-94382
📛 CVE Title
Beszel before 0.19.0 Insecure Direct Object Reference via user-alerts
Description
Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access. Attackers can supply arbitrary system IDs in the request body to register alert rules and receive notifications disclosing target system names and metrics.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- VulnCheck
- CVSS severity
- LOW
- CVSS score
- 2.3 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N- Effective score
- 2.3 / 10 LOW source: CNA overview
- CWE(s)
-
CWE-639 - Reserved
- 2026-09-21
- Published
- 2026-09-21 12:59 UTC
- Last updated
- 2026-09-21 14:12 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/94xxx/CVE-2026-94382.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-21 14:17:30 UTC
- NVD last modified
- 2026-09-21 15:17:39 UTC
- NVD CVSS v3.1
- 4.2 / 10 MEDIUM source: disclosure@vulncheck.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N- Exploitability subscore
- 1.6 / 10
- Impact subscore
- 2.5 / 10
- EPSS score
- 0.0022 (probability of exploitation in next 30 days)
- EPSS percentile
- 12.26% vs all CVEs — higher = more likely to be exploited, as of 2026-09-22
NVD / KEV / EPSS data refreshed 2026-09-23 02:32 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-83909 - Assigner
- VulnCheck
- Published
- Sep 21, 2026, 12:59:39 PM
- Updated
- Sep 21, 2026, 2:12:10 PM
- EUVD base score (CVSS 4.0)
-
2.3 / 10
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.2200
- Vendors
- henrygd
- Products
-
beszel (0 <0.19.0)
- Aliases
-
GHSA-x7pw-mf2h-rgr4
ENISA description: Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access. Attackers can supply arbitrary system IDs in the request body to register alert rules and receive notifications disclosing target system names and metrics.
EUVD references (6)
- https://github.com/henrygd/beszel/security/advisories/GHSA-759g-ch5m-2gch
- https://github.com/henrygd/beszel/commit/6f92b9396dfbacaf71c20444d175af78e0517409
- https://github.com/henrygd/beszel/blob/v0.18.8/internal/alerts/alerts_api.go#L19-L80
- https://github.com/henrygd/beszel/releases/tag/v0.19.0
- https://github.com/henrygd/beszel
- https://www.vulncheck.com/advisories/beszel-before-0.19.0-insecure-direct-object-reference-via-user-alerts
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| henrygd | beszel |
0 (affected),
0.19.0 (unaffected)
|
— |
Vendor references (6)
References embedded in the original CVE record by the assigning CNA.
- GitHub Security Advisory (GHSA-759g-ch5m-2gch) vendor-advisory
- Patch Commit patch
- Vulnerable UpsertUserAlerts handler at v0.18.8 technical-description
- beszel v0.19.0 Release Notes release-notes
- https://github.com/henrygd/beszel product
- VulnCheck Advisory: Beszel before 0.19.0 Insecure Direct Object Reference via user-alerts third-party-advisory
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (7)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/henrygd/beszel disclosure@vulncheck.com
- https://github.com/henrygd/beszel/blob/v0.18.8/internal/alerts/alerts_api.go#L19-L80 disclosure@vulncheck.com
- https://github.com/henrygd/beszel/commit/6f92b9396dfbacaf71c20444d175af78e0517409 disclosure@vulncheck.com
- https://github.com/henrygd/beszel/releases/tag/v0.19.0 disclosure@vulncheck.com
- https://github.com/henrygd/beszel/security/advisories/GHSA-759g-ch5m-2gch disclosure@vulncheck.com
- https://github.com/henrygd/beszel/security/advisories/GHSA-759g-ch5m-2gch 134c704f-9b21-4f2e-91b3-4a467353bcc0
- https://www.vulncheck.com/advisories/beszel-before-0.19.0-insecure-direct-object-reference-via-user-alerts disclosure@vulncheck.com
Remediations (10)
-
web:cybersecuritynews.com
Oracle has released 943 new security patches in its August 2026 Critical Security Patch Update, addressing flaws across its enterprise software portfolio. The release includes several critical Oracle WebLogic Server vulnerabilities that could allow an unauthenticated remote attacker to take complete ...
2026-09-23 15:41 UTC -
web:github.com
CVEfixes: Automated Collection of Vulnerabilities and Their Fixes from Open-Source Software - secureIT-project/CVEfixes
2026-09-23 15:41 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-09-23 15:41 UTC -
web:msrc.microsoft.com
Access Microsoft Security Response Center's guide to address vulnerabilities, manage security risks, and keep your systems protected with the latest updates.
2026-09-23 15:41 UTC -
web:sec.cloudapps.cisco.com
On September 16, 2026 , the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the ...
2026-09-23 15:41 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-23 15:41 UTC -
web:support.microsoft.com
This cumulative update for Windows Server 2022 (KB5122882), includes the latest security fixes and improvements, along with non-security updates from last month's optional preview release. Visit the Windows release health dashboard for the latest status on this release. Announcements and messages This section provides key notifications related to this release, including announcements, change ...
2026-09-23 15:41 UTC -
web:www.microsoft.com
Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed. You can choose the type of updates for which you want to be notified: Major ...
2026-09-23 15:41 UTC -
web:www.oracle.com
This Critical Patch Update contains 1448 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.
2026-09-23 15:41 UTC -
web:www.oracle.com
Additional CVEs addressed are: The patch for CVE - 2026 -34481 also addresses CVE - 2026 -34477, CVE - 2026 -34478, CVE - 2026 -34479, and CVE - 2026 -34480. Oracle Fusion Middleware Risk Matrix This Critical Security Patch Update contains 106 new security patches for Oracle Fusion Middleware. 53 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a ...
2026-09-23 15:41 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-94382.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94382",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T14:12:03.342785Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T14:12:10.208Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/henrygd/beszel/security/advisories/GHSA-759g-ch5m-2gch"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/henrygd/beszel",
"product": "beszel",
"vendor": "henrygd",
"versions": [
{
"lessThan": "0.19.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.19.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:beszel:beszel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "0.19.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Onetatcode"
},
{
"lang": "en",
"type": "finder",
"value": "DeathXcorE"
},
{
"lang": "en",
"type": "finder",
"value": "DavidCarliez"
},
{
"lang": "en",
"type": "finder",
"value": "ka3n1x"
}
],
"datePublic": "2026-09-20T22:42:38.000Z",
"descriptions": [
{
"lang": "en",
"value": "Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access. Attackers can supply arbitrary system IDs in the request body to register alert rules and receive notifications disclosing target system names and metrics."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 2.3,
"baseSeverity": "LOW",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.2,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T12:59:39.971Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-759g-ch5m-2gch)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/henrygd/beszel/security/advisories/GHSA-759g-ch5m-2gch"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/henrygd/beszel/commit/6f92b9396dfbacaf71c20444d175af78e0517409"
},
{
"name": "Vulnerable UpsertUserAlerts handler at v0.18.8",
"tags": [
"technical-description"
],
"url": "https://github.com/henrygd/beszel/blob/v0.18.8/internal/alerts/alerts_api.go#L19-L80"
},
{
"name": "beszel v0.19.0 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/henrygd/beszel/releases/tag/v0.19.0"
},
{
"tags": [
"product"
],
"url": "https://github.com/henrygd/beszel"
},
{
"name": "VulnCheck Advisory: Beszel before 0.19.0 Insecure Direct Object Reference via user-alerts",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/beszel-before-0.19.0-insecure-direct-object-reference-via-user-alerts"
}
],
"title": "Beszel before 0.19.0 Insecure Direct Object Reference via user-alerts",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-94382",
"datePublished": "2026-09-21T12:59:39.971Z",
"dateReserved": "2026-09-21T12:48:31.169Z",
"dateUpdated": "2026-09-21T14:12:10.208Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}