Impact
Nezha Dashboard versions prior to 2.3.5 contain a task type validation bypass that allows users with the nezha:service:write privilege to submit tasks with any type through the service API. The shared protobuf Task.Type namespace between service monitors and privileged operations lets an attacker deliver command execution or Agent configuration tasks to any Agent within their authorization scope. CVE-2026-101086 is a CWE-269 weakness that can compromise confidentiality, integrity, and availability of the infrastructure managed by Nezha.
Affected Systems
The vulnerability affects the Nezha Dashboard component (nezhahq:nezha) and specifically impacts all releases older than 2.3.5. Any user who can authenticate and possesses the nezha:service:write role is able to exploit the flaw. The attack does not require a public vulnerability; it relies on legitimate API access and proper permissions.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability presents high impact if exploited, though the EPSS score is not available. The flaw is not listed in CISA’s KEV catalog. An attacker would need only authorized API access to a Nezha instance; the code execution path requires the ability to submit privileged task types, which is available to users with write scope. Given the absence of a publicly available exploit and the requirement for valid credentials, the immediate risk is moderate to high for customers that grant unnecessary permissions or run outdated Nezha dashboards.
OpenCVE Enrichment