CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-40077

CVE-2026-40077: Insecure Direct Object Reference in Beszel Hub API

Amit Schendel
Amit Schendel
Senior Security Researcher

Apr 10, 2026·5 min read·48 visits

Executive Summary (TL;DR)

An IDOR flaw in Beszel Hub allows authenticated users to access other users' systems by providing a 15-character system ID. The patch in version 0.18.7 introduces explicit ownership validation.

CVE-2026-40077 is an Insecure Direct Object Reference (IDOR) vulnerability in the Beszel Hub API prior to version 0.18.7. The flaw allows authenticated users to bypass authorization controls and access sensitive container logs, retrieve systemd metadata, or trigger SMART disk scans on monitoring agents belonging to other users.

Vulnerability Overview

Beszel is a server monitoring platform built around a central Hub and distributed agents. The Hub component utilizes the PocketBase framework to manage relationships, users, and monitoring targets. PocketBase inherently provides Relationship-Based Access Control (RBAC) on standard collection operations. The Beszel Hub implements several custom API routes to proxy requests directly to remote monitoring agents.

Prior to version 0.18.7, the Beszel Hub failed to enforce proper authorization constraints on these custom API routes. An Insecure Direct Object Reference (IDOR) vulnerability existed within the handlers responsible for interacting with the monitoring agents. The flaw allowed any authenticated user to interact with systems associated with other users.

The vulnerability relies on the attacker knowing or obtaining a target system's 15-character alphanumeric ID. By supplying this ID to specific endpoints, an attacker can bypass the intended access controls. The affected endpoints primarily handle fetching container logs, retrieving systemd metadata, and initiating SMART hardware data refreshes.

Root Cause Analysis

The root cause of CVE-2026-40077 is a Broken Access Control implementation within the custom API handlers in internal/hub/api.go. The handlers correctly extracted the system query parameter but failed to cryptographically or logically verify that the authenticated user owned the specified system.

When processing a request, the vulnerable code invoked h.sm.GetSystem(systemID) to retrieve the system record. The method only verified that the 15-character system ID existed within the database. It did not intersect the system record with the users relation field associated with the requester's JSON Web Token (JWT) identity.

Because the PocketBase RBAC rules only apply to the framework's auto-generated CRUD endpoints, the custom proxy routes required explicit, manual authorization checks. The omission of this manual check meant that the application blindly trusted the user-supplied system ID, proxying the request to the target agent regardless of the user's actual permissions.

Code Analysis

The vulnerability resided in the custom request handlers that bridged the PocketBase HTTP layer and the remote agents. The vulnerable implementation directly utilized the systemID provided in the HTTP GET query parameters.

func (h *Hub) containerRequestHandler(e *core.RequestEvent) error {
    systemID := e.Request.URL.Query().Get("system")
    // Vulnerable: Retrieves system without verifying membership
    system, err := h.sm.GetSystem(systemID) 
    if err != nil {
        return e.JSON(http.StatusNotFound, "System not found")
    }
    // Proceed to contact agent...
}

The remediation introduced in commit ba10da1b9f13455f2879336445102a45eb6cb07b implemented a strict authorization gate. The developers added a HasUser method that validates the requester's ID (e.Auth.Id) against the users slice embedded within the system record.

func (h *Hub) containerRequestHandler(e *core.RequestEvent, fetchFunc func(*system.System, string) (string, error), responseKey string) error {
    systemID := e.Request.URL.Query().Get("system")
    containerID := e.Request.URL.Query().Get("container")
 
    system, err := h.sm.GetSystem(systemID)
    // Patched: Mandatory membership validation using HasUser()
    if err != nil || !system.HasUser(e.App, e.Auth.Id) {
        return e.NotFoundError("", nil) 
    }
    // ...
}

To prevent ID enumeration, the patched implementation returns a generic 404 Not Found error for both non-existent systems and unauthorized access attempts. This design choice obscures the validity of guessed system IDs from potential attackers.

Exploitation Methodology

Exploitation of CVE-2026-40077 requires an attacker to possess a valid authentication token and the target system's 15-character alphanumeric ID. The attacker first registers or compromises a low-privileged user account on the target Beszel Hub to obtain a valid JWT.

The attacker must then acquire the target systemID. While these IDs are randomly generated strings, they are occasionally leaked through secondary Hub API endpoints or misconfigurations. Once the ID is obtained, the attacker crafts direct HTTP requests to the vulnerable custom endpoints.

An example exploit request targeting Docker container logs involves appending the target system ID and container ID to the endpoint URI. The attacker issues a GET request to /api/beszel/containers/logs?system=[TARGET_ID]&container=[CONTAINER_ID]. The Hub processes the request, bypasses authorization, and returns the raw log output from the remote agent.

Impact Assessment

The primary impact of this vulnerability is partial information disclosure. An attacker can read real-time logs from any Docker container running on a targeted, unauthorized system. Container logs frequently contain sensitive operational data, including application secrets, Personally Identifiable Information (PII), API keys, and environment variables.

Beyond information disclosure, the vulnerability enables unauthorized administrative actions on the remote agents. Attackers can force the agents to initiate SMART disk scans by POSTing to /api/beszel/smart/refresh?system=[TARGET_ID]. Repeatedly triggering these hardware operations can lead to localized resource exhaustion and premature wear on storage mediums.

Attackers can also retrieve systemd unit properties via the /api/beszel/systemd/logs equivalent endpoints. This capability allows malicious actors to map the internal architecture and service dependencies of the target host, facilitating further lateral movement or targeted exploitation. The overall severity is moderated by the requirement for authentication and prior knowledge of the 15-character system ID.

Remediation and Hardening

The vulnerability is fully addressed in Beszel version 0.18.7. Organizations deploying Beszel Hub must upgrade to this release or later to ensure the custom API proxy routes correctly enforce user ownership validation. The patch relies on the HasUser mechanism to permanently close the IDOR vector.

In addition to the core authorization patch, the developers introduced secondary hardening measures in commit 5463a38f0f426b45272dff7bffcd351fe5ddcf03. The implementation now includes requireAdminRole and excludeReadOnlyRole middleware functions. These middlewares prevent low-privileged accounts (such as 'readonly' users) from accessing sensitive administrative tokens or triggering SMART refreshes, effectively enforcing the principle of least privilege.

If immediate patching is not possible, administrators should review user roles within the Hub. Organizations should ensure that guest or untrusted accounts are restricted to 'readonly' permissions or removed entirely. Additionally, operators should audit access logs for unusual HTTP 404 errors or high-frequency requests to /api/beszel/containers/logs, which indicate active system ID enumeration attempts.

Official Patches

henrygdFixed Version Release (v0.18.7)

Fix Analysis (2)

Technical Appendix

CVSS Score
3.5/ 10
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
EPSS Probability
0.05%
Top 85% most exploited

Affected Systems

Beszel Hub APIBeszel Monitoring Agents

Affected Versions Detail

Product
Affected Versions
Fixed Version
Beszel
henrygd
< 0.18.70.18.7
AttributeDetail
CWE IDCWE-184, CWE-639
Attack VectorNetwork
CVSS Base Score3.5
EPSS Percentile14.91%
ImpactInformation Disclosure
Exploit StatusProof-of-Concept
KEV ListedFalse

MITRE ATT&CK Mapping

T1592Gather Victim Host Information
Reconnaissance
T1078Valid Accounts
Initial Access
CWE-639
Authorization Bypass Through User-Controlled Key

Insecure Direct Object Reference (IDOR)

Known Exploits & Detection

GitHub AdvisoryProof-of-Concept logic documented in advisory, outlining target endpoint queries.

Vulnerability Timeline

Vulnerability discovered and reported.
2026-03-27
Hub-side authorization patch (ba10da1) committed.
2026-04-01
Official CVE-2026-40077 published.
2026-04-09
Fixed version 0.18.7 released.
2026-04-09

References & Sources

  • [1]Official Security Advisory (GitHub)
  • [2]Fixed Version Release (v0.18.7)
  • [3]Core Authorization Patch
  • [4]Middleware Refactor Patch
  • [5]CVE Record

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•23 minutes ago•CVE-2026-105749
6.5

CVE-2026-105749: Unbounded Table Attributes in Docling Backends Leads to Resource Exhaustion

An uncontrolled resource consumption vulnerability exists in the Docling document conversion library. Maliciously structured HTML, JATS, ODS, or BoxNote inputs containing table cells with excessively large 'rowspan' or 'colspan' attribute values trigger algorithmic complexity conditions. This allows unauthenticated remote attackers to initiate resource exhaustion states, crashing or hanging the target document processing pipeline while bypassing configured timeouts.

Amit Schendel
Amit Schendel
1 views•6 min read
•about 1 hour ago•CVE-2026-105748
4.3

CVE-2026-105748: Local File Inclusion and Arbitrary File Disclosure in Docling Document Parser

A Local File Inclusion (LFI) and Arbitrary File Disclosure vulnerability exists in Docling and Docling Slim versions >= 2.16.0 up to 2.131.0. When parsing serialized DoclingDocument structures using the JSON input format, the backend fails to restrict image URI schemes, allowing remote attackers to retrieve local files and verify path existence on the host system during embedded document export.

Amit Schendel
Amit Schendel
5 views•5 min read
•about 2 hours ago•CVE-2026-105744
7.5

CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine

Docling, a tool for parsing and processing diverse document formats, is vulnerable to arbitrary file read, arbitrary file write, and potential remote code execution (RCE) in versions 2.94.0 through 2.131.0. The vulnerability occurs when applications configure Docling to use the Tectonic engine for rendering TikZ diagrams into images. Because the compilation did not restrict hazardous TeX primitives or sandbox the environment, an attacker can supply crafted documents containing malicious TikZ definitions to access or modify local files and execute arbitrary commands under the privileges of the processing application.

Amit Schendel
Amit Schendel
6 views•7 min read
•about 3 hours ago•CVE-2026-105743
4.0

CVE-2026-105743: Server-Side Request Forgery Guard Bypass in Docling Document Conversion Engine

An SSRF guard bypass vulnerability in the Docling document conversion engine allows unauthenticated attackers to bypass internal IP access controls. The vulnerability exists due to a DNS rebinding Time-of-Check Time-of-Use (TOCTOU) condition, URL authority parsing inconsistencies, and unvalidated network requests triggered during headless browser page rendering.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 4 hours ago•CVE-2026-105742
3.7

CVE-2026-105742: Sensitive Custom Header Leakage in Docling Image Resource Loader

A technical analysis of CVE-2026-105742 (GHSA-p3fw-7699-7926), a sensitive information disclosure vulnerability in the Docling document processing library. Vulnerable versions of Docling indiscriminately forward custom HTTP headers, such as authentication tokens, to arbitrary third-party origins and during cross-origin redirects while fetching remote image assets from untrusted HTML and EPUB documents.

Alon Barad
Alon Barad
6 views•6 min read
•about 5 hours ago•CVE-2026-106121
4.9

CVE-2026-106121: Denial of Service via Infinite Loop in RabbitMQ Java Client JSON Parser

CVE-2026-106121 is a Denial of Service (DoS) vulnerability in the RabbitMQ Java Client library (amqp-client) affecting versions prior to 5.37.0. The vulnerability resides in the legacy, custom JSON-RPC parsing class com.rabbitmq.tools.json.JSONReader. When parsing malformed or truncated payloads ending within a quoted string or single-line comment, the parser's scanner enters an infinite loop. This occurs because the loop lacks an exit condition for the end-of-input sentinel character returned by the iterator, leading to either CPU exhaustion or a JVM crash from an OutOfMemoryError.

Amit Schendel
Amit Schendel
8 views•6 min read