Nezha Monitoring contains a vulnerability where a low-privileged user can trigger arbitrary commands across all monitored servers, resulting in cross-...
Description
Nezha Monitoring contains a vulnerability where a low-privileged user can trigger arbitrary commands across all monitored servers, resulting in cross-tenant remote code execution.
AI Analyst Comment
Remediation
Update Nezha Multiple Products to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Nezha
PRODUCT: Monitoring
AFFECTED_VERSIONS: From version 1.4.0 to before version 2.0.8
---END_METADATA---
Description Summary:
Nezha Monitoring contains a vulnerability where a low-privileged user can trigger arbitrary commands across all monitored servers, resulting in cross-tenant remote code execution.
Executive Summary:
A critical RCE vulnerability in Nezha Monitoring allows authenticated users to execute arbitrary commands on all managed servers, regardless of tenant boundaries.
Vulnerability Details
CVE-ID: CVE-2026-46716
Affected Software: Nezha Monitoring
Affected Versions: From version 1.4.0 to before version 2.0.8
Vulnerability: A RoleMember user can create a malicious cron task that pushes arbitrary commands to the global server pool. These commands are executed by agents on all monitored servers, bypassing tenant isolation.
Business Impact
This is a critical cross-tenant Remote Code Execution (RCE) vulnerability. An attacker with minimal access can gain control over every server managed by the Nezha instance, leading to a complete compromise of the entire server fleet. Given the CVSS score of 9.9, this vulnerability poses an extreme threat to organizational operations.
Remediation Plan
Immediate Action: Update Nezha Monitoring to version 2.0.8 immediately.
Proactive Monitoring: Audit existing cron tasks within the Nezha dashboard for any unauthorized or suspicious commands. Review agent execution logs for command execution patterns.
Compensating Controls: Restrict access to the Nezha dashboard interface to a limited set of trusted administrators until the patch is applied.
Exploitation Status
Public Exploit Available: True
Analyst Notes: As of Jun 12, 2026, a public exploit exists for this vulnerability. The risk of exploitation is extremely high and immediate remediation is required.
Analyst Recommendation
The ability to execute arbitrary code across an entire fleet of managed servers is a catastrophic risk. Administrators must update to version 2.0.8 immediately to prevent potential mass compromise of their server infrastructure.