CVE Explorer
CVE-2026-40077
Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied system ID and proceed without further checks that the user should have access to that system. As a result, any authenticated user can access these routes for any system if they know the system's ID. System IDs are random 15 character alphanumeric strings, and are not exposed to all users. However, it is theoretically possible for an authenticated user to enumerate a valid system I
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"beszel","vendor":"henrygd","versions":[{"status":"affected","version":"< 0.18.7"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:67512a5526e69c86213684483b370264a0ecf32f9879e5a889b13ca0f0f870df · sha256:bdedace7a365697a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:67512a5526e69c86213684483b370264a0ecf32f9879e5a889b13ca0f0f870df · sha256:bdedace7a365697a… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-184","description":"CWE-184: Incomplete List of Disallowed Inputs","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:67512a5526e69c86213684483b370264a0ecf32f9879e5a889b13ca0f0f870df · sha256:bdedace7a365697a… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/henrygd/beszel/releases/tag/v0.18.7","tags":["x_refsource_MISC"],"url":"https://github.com/henrygd/beszel/releases/tag/v0.18.7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:67512a5526e69c86213684483b370264a0ecf32f9879e5a889b13ca0f0f870df · sha256:bdedace7a365697a… · /containers/cna/references/1
{"name":"https://github.com/henrygd/beszel/security/advisories/GHSA-5f5r-95pg-xrpm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/henrygd/beszel/security/advisories/GHSA-5f5r-95pg-xrpm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:67512a5526e69c86213684483b370264a0ecf32f9879e5a889b13ca0f0f870df · sha256:bdedace7a365697a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.