PT-2026-94087 · Dgtlmoon+1 · Changedetection.Io

·

CVE-2026-92815

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions changedetection.io versions prior to 0.60.7
Description An issue exists where the software fails to validate the Goto URL action within browser steps. This allows unauthenticated attackers to access internal network addresses by providing arbitrary internal URLs through the optional value parameter, enabling the retrieval of responses from restricted locations.
Recommendations Update changedetection.io to version 0.60.7 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92815

Affected Products

Changedetection.Io