Brute Force Vulnerability in changedetection.io Login Process
CVE-2026-71205
5.3MEDIUM
What is CVE-2026-71205?
The login mechanism of changedetection.io is vulnerable due to a reliance on a single PBKDF2-HMAC-SHA256 hash for password verification. This design choice, coupled with the absence of rate limiting for login attempts, allows attackers to perform brute force attacks without facing lockout or account specific restrictions. As the application operates under a universal password without individualized user accounts, successful exploitation can lead to complete administrative control, enabling unauthorized access to sensitive information, including the ability to regenerate API tokens.
Affected Version(s)
changedetection.io 0.55.7
