Brute Force Vulnerability in changedetection.io Login Process
CVE-2026-71205

5.3MEDIUM

Key Information:

Vendor

Dgtlmoon

Vendor
CVE Published:
5 August 2026

What is CVE-2026-71205?

The login mechanism of changedetection.io is vulnerable due to a reliance on a single PBKDF2-HMAC-SHA256 hash for password verification. This design choice, coupled with the absence of rate limiting for login attempts, allows attackers to perform brute force attacks without facing lockout or account specific restrictions. As the application operates under a universal password without individualized user accounts, successful exploitation can lead to complete administrative control, enabling unauthorized access to sensitive information, including the ability to regenerate API tokens.

Affected Version(s)

changedetection.io 0.55.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eldor Nabijonov
.