CVE-2026-27734Disclosure(beszel / beszel)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/containers/logs and GET /api/beszel/containers/info pass the user-supplied "container" query parameter to the agent without validation. The agent constructs Docker Engine API URLs using fmt.Sprintf with the raw value instead of url.PathEscape(). Since Go's http.Client does not sanitize `../` sequences from URL paths sent over unix sockets, an authenticated user (including readonly role) can traverse to arbitrary Docker API endpoints on agent hosts, exposing sensitive infrastructure details. Version 0.18.4 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • beszel

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-27); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
beszel

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Technical Details · 2026-02-27: 102-2702-28
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27734 Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/containers/logs and GET /api/beszel/containers/… https://www.cve.org/CVERecord?id=CVE-2026-27734

    Post summary

    The text announces CVE‑2026‑27734 as affecting Beszel’s authenticated API endpoints prior to version 0.18.2, without providing additional technical details, PoC, or mitigation information.

    00000146
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27734: Docker API Path Traversal in Beszel Agent via Unsanitized Input A path traversal vulnerability exists in the Beszel server monitoring agent, allowing authenticated users to access arbitrary Docker Engine API endpoints. The vulnerabilit... https://cvereports.com/reports/CVE-2026-27734

    Post summary

    A path traversal vulnerability in Beszel server monitoring agent allows authenticated users to access arbitrary Docker Engine API endpoints via unsanitized input.

    0000051
    32 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbeszelbeszel---

Explore more