Web Application Vulnerability in Changedetection.io by dgtlmoon
CVE-2026-35490
9.8CRITICAL
What is CVE-2026-35490?
Changedetection.io, an open-source web page change detection tool, contains a vulnerability that affects the authentication mechanism for its routes. Prior to version 0.54.8, the improper ordering of the @login_optionally_required decorator in the Flask framework leads to a situation where the authentication wrapper is not applied. This flaw causes a silent disablement of authentication, leaving potentially sensitive routes unprotected. Users are advised to update to version 0.54.8 or later to mitigate this issue.
Affected Version(s)
changedetection.io < 0.54.8
