CVE-2026-53521
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, PATCH /server/{id} accepts and persists nonexistent ddns_profiles IDs for a member-owned server. If another user later creates a DDNS profile with one of those IDs, the DDNS worker resolves the stored ID and dispatches an update using the other user's DDNS profile configuration in the context of the attacker's server. This issue has been patched in version 2.1.0.
- Affected products
- Nezha Monitoring
- Fix
- Available
- CVSS 3.1
- 6.4 MEDIUM
- EPSS
- 0.2% (13th percentile)
- Weakness
- CWE-863
- NVD status
- Deferred
- Published
- 2026-06-12
CVE-2026-53521 at NVD
No indexed exploits for CVE-2026-53521 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-53521 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.