CVE-2026-47120
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/06/2026
Last modified:
12/06/2026
Description
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check). This issue has been patched in version 2.0.8.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH



