PT-2026-31706 · Beszel · Beszel
Published
2026-04-09
·
Updated
2026-04-28
·
CVE-2026-40077
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Beszel versions prior to 0.18.7
Description
Beszel is a server monitoring platform. Some API endpoints in the Beszel hub accept a user-supplied system ID without verifying user access permissions. This allows authenticated users to access routes for any system if they know the system's ID. System IDs are 15-character alphanumeric strings, and while not generally exposed, can potentially be enumerated by authenticated users through the web API. Accessing container endpoints also requires enumerating 12-digit hexadecimal container IDs.
Recommendations
Update to version 0.18.7 or later.
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Beszel