PT-2026-60259 · Dashy · Dashy

CVE-2026-46485

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Dashy versions prior to 4.0.8
Description Deployments using OIDC (OpenID Connect, an identity layer on top of the OAuth 2.0 protocol) allow unauthenticated users or authenticated users without administrator privileges to modify the main config.yaml file. This occurs through the config-saving functionality, bypassing established permissions and potentially leading to unauthorized dashboard configuration changes and service disruption.
Recommendations Update to version 4.0.8.

Exploit

Fix

Improper Access Control

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46485
GHSA-VJJ9-FMVR-6H3P

Affected Products

Dashy