PT-2026-31706 · Beszel · Beszel

Published

2026-04-09

·

Updated

2026-04-28

·

CVE-2026-40077

CVSS v3.1

3.5

Low

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Beszel versions prior to 0.18.7
Description Beszel is a server monitoring platform. Some API endpoints in the Beszel hub accept a user-supplied system ID without verifying user access permissions. This allows authenticated users to access routes for any system if they know the system's ID. System IDs are 15-character alphanumeric strings, and while not generally exposed, can potentially be enumerated by authenticated users through the web API. Accessing container endpoints also requires enumerating 12-digit hexadecimal container IDs.
Recommendations Update to version 0.18.7 or later.

Fix

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

CVE-2026-40077
GHSA-5F5R-95PG-XRPM

Affected Products

Beszel