CVE-2026-101089 LOW

CVE-2026-101089: Nezha before 2.2.7 Information Disclosure via /api/v1/profile

Vendor Nezhahq
Product nezha
Weakness CWE-522 · Insufficiently protected credentials
Published September 27, 2026
Last update September 28, 2026

CVSS base score

2.3/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract password hashes and perform offline cracking attacks without rate limiting or audit trail constraints.

Key dates

02Disclosure timeline

September 27, 2026 CVE published
September 28, 2026 Record updated