Web Application Vulnerability in Changedetection.io by dgtlmoon
CVE-2026-35490

9.8CRITICAL

Key Information:

Vendor

Dgtlmoon

Vendor
CVE Published:
7 April 2026

What is CVE-2026-35490?

Changedetection.io, an open-source web page change detection tool, contains a vulnerability that affects the authentication mechanism for its routes. Prior to version 0.54.8, the improper ordering of the @login_optionally_required decorator in the Flask framework leads to a situation where the authentication wrapper is not applied. This flaw causes a silent disablement of authentication, leaving potentially sensitive routes unprotected. Users are advised to update to version 0.54.8 or later to mitigate this issue.

Affected Version(s)

changedetection.io < 0.54.8

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.