PT-2026-28800 · Unknown · Nezha Monitoring

CVE-2026-53521

·

Published

2026-03-28

·

Updated

2026-07-30

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Nezha Monitoring versions 2.0.14 through 2.0.19
Description The software allows the 'PATCH /server/{id}' endpoint to accept and store nonexistent ddns profiles IDs for a server owned by a member. If a different user subsequently creates a DDNS profile using one of those IDs, the DDNS worker resolves the stored ID and sends an update using the second user's DDNS profile configuration within the context of the first user's server.
Recommendations Update to version 2.1.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53521
GHSA-39G2-8X68-PMX8
GO-2026-5826
OPENSUSE-SU-2026:21483-1

Affected Products

Nezha Monitoring