CVE-2026-53521

MEDIUM

Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context

Title source: cna
STIX 2.1

Description

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, PATCH /server/{id} accepts and persists nonexistent ddns_profiles IDs for a member-owned server. If another user later creates a DDNS profile with one of those IDs, the DDNS worker resolves the stored ID and dispatches an update using the other user's DDNS profile configuration in the context of the attacker's server. This issue has been patched in version 2.1.0.

References (1)

Core 1
Core References

Scores

CVSS v3 6.4
EPSS 0.0023
EPSS Percentile 13.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
nezhahq/nezha >= 2.0.14, < 2.1.0
Published Jun 12, 2026
Tracked Since Jun 13, 2026