OVERVIEW CVE-2026-40077 is an authorization bypass vulnerability in Beszel, an open-source server monitoring platform. Versions prior to 0.18.7 contain multiple API endpoints that fail to validate whether authenticated users have access to requested systems. This allows any authenticated user to access monitoring data for arbitrary systems by providing the target system's ID, which can theoretically be enumerated through API calls. SEVERITY The vulnerability carries a CVSS v3.1 base score of 3.1 (Low) with a network attack vector requiring low privilege authentication and high attack complexity. The impact is limited to confidentiality loss, with no integrity or availability risk. The EPSS score of 0.00057 indicates minimal current exploitation likelihood relative to the broader CVE landscape, positioning this as a low-probability threat in active threat environments. EXPLOITATION STATUS There is no evidence of active exploitation, and CVE-2026-40077 does not appear on the Known Exploited Vulnerabilities catalog. The vulnerability has not achieved Hot List status, suggesting limited community attention or public exploitation attempts. The practical barriers to exploitation—requiring knowledge of valid system IDs (15-character random strings) and container IDs (12-digit hexadecimal)—further reduce real-world attack likelihood despite theoretical enumerability through API reconnaissance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.18.7CPE matchmatch criteria | cpe:2.3:a:beszel:beszel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.