PT-2026-60259 · Dashy · Dashy
CVE-2026-46485
·
Published
2026-07-15
·
Updated
2026-07-15
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Dashy versions prior to 4.0.8
Description
Deployments using OIDC (OpenID Connect, an identity layer on top of the OAuth 2.0 protocol) allow unauthenticated users or authenticated users without administrator privileges to modify the main
config.yaml file. This occurs through the config-saving functionality, bypassing established permissions and potentially leading to unauthorized dashboard configuration changes and service disruption.Recommendations
Update to version 4.0.8.
Exploit
Fix
Improper Access Control
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dashy