CVE-2026-53521 Details
Description
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, PATCH /server/{id} accepts and persists nonexistent ddns_profiles IDs for a member-owned server. If another user later creates a DDNS profile with one of those IDs, the DDNS worker resolves the stored ID and dispatches an update using the other user's DDNS profile configuration in the context of the attacker's server. This issue has been patched in version 2.1.0.
A vulnerability in Nezha Monitoring versions 2.0.14 prior to 2.1.0 allows for unauthorized updates to a user's DDNS profile via a second-order authorization bypass. The issue arises in the 'PATCH /server/{id}' endpoint, where nonexistent DDNS profile IDs can be stored and later resolved to another user's profile once it is created. This exploitation occurs in the context of the original server owner, potentially leading to unauthorized DDNS updates using the victim's profile configuration.
Users are advised to update to Nezha Monitoring version 2.1.0 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nezhahq/nezha/security/advisories/GHSA-39g2-8x68-pmx8 | CISA-ADP | AdvisoryRemedyVendor |
| https://github.com/nezhahq/nezha/security/advisories/GHSA-39g2-8x68-pmx8 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Nezha Monitoring | >= 2.0.14, < 2.1.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |
Volerion