PatchSiren cyber security CVE debrief
CVE-2026-101086 nezhahq CVE debrief
CVE-2026-101086 debrief based on the supplied source corpus. Nezha Dashboard versions before 2.3.5 are vulnerable due to insufficient restriction of service monitor task types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. This could lead to command execution or Agent configuration tasks within their authorization scope. Defenders should assess exposure, verify versions, and focus on service monitor task type validation and user access controls.
- Vendor
- nezhahq
- Product
- nezha
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-27
- Original CVE updated
- 2026-09-27
- Advisory published
- 2026-09-27
- Advisory updated
- 2026-09-27
Who should care
Defenders responsible for Nezha Dashboard deployments should assess exposure and verify versions, focusing on service monitor task type validation and user access controls. They should also review compensating controls for exposed systems, monitor for suspicious task submissions, and track exceptions and retest remediated assets.
Why it matters
CVE-2026-101086 allows authenticated users to submit privileged tasks in Nezha Dashboard versions before 2.3.5, potentially leading to command execution or Agent configuration changes within their authorization scope.
- Verify Nezha Dashboard version and update to 2.3.5 or later.
- Restrict service monitor task types to supported probe types.
- Monitor for suspicious task submissions by authenticated users.
Technical summary
CVE-2026-101086 is a vulnerability in Nezha Dashboard versions before 2.3.5, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. This could lead to command execution or Agent configuration tasks within their authorization scope. The vulnerability arises from the shared protobuf Task.Type namespace between service monitors and privileged operations, enabling attackers to deliver command execution or Agent configuration tasks to Agents within their authorization scope.
Defensive priority
Defenders should prioritize verifying Nezha Dashboard versions before 2.3.5 for vulnerability to CVE-2026-101086, focusing on service monitor task type validation.
Recommended defensive actions
- Verify Nezha Dashboard version and update to 2.3.5 or later if vulnerable.
- Restrict service monitor task types to supported probe types.
- Monitor for suspicious task submissions by authenticated users.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in Nezha Dashboard versions before 2.3.5, which allows authenticated users to submit privileged task types. Official sources include CVE Program and NIST NVD records.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-101086 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-101086
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-101086 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-101086
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/nezhahq/nezha/commit/38824dbc11a63964c5b9296ae4c68e62b34fa04b
-
Source reference
Unverified legacy reference
URL: https://github.com/nezhahq/nezha/security/advisories/GHSA-grrw-fx36-fv32
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/nezha-dashboard-before-2.3.5-task-type-validation-bypass
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.