Impact
An authenticated RoleMember can acquire a WebSocket stream UUID from logs or browser history and connect to another user's terminal or file‑manager session. Because the stream identifiers are not bound to the creating user, the attacker can read and write files on the target server and execute shell commands, granting full remote control over the target. This capability violates confidentiality, integrity, and availability principles and is a classic example of authorization bypass (CWE‑639) and missing authorization (CWE‑862).
Affected Systems
Nezha Monitoring versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 are affected. The vulnerability is fixed in version 2.0.10. The affected product is manufactured by nezhahq.
Risk and Exploitability
With a CVSS score of 9.9, this flaw is considered critical. The EPSS score is not available, but the lack of mitigation in earlier releases and the ease of obtaining a valid stream UUID make exploitation highly likely for anyone who can authenticate as a RoleMember. The vulnerability is not listed in CISA’s KEV catalog, yet the high severity and lack of an official workaround mean that the risk remains significant until the patch is applied.
OpenCVE Enrichment