Sceawere
Vulnerability Detail
CVE-2026-95271UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Improper Authentication in changedetection.io
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 3h ago
- Vendor
- dgtlmoon
- Product
- changedetection.io
- Attack Type
- Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-22T13:17:12.767Z",
"pubdate": "2026-09-22T13:17:12.767Z",
"executiveSummary": "A critical vulnerability exists in dgtlmoon changedetection.io up to version 0.60.7 within the Authentication Hook component. The vulnerability is classified as improper authentication, which allows unauthorized actors to bypass security controls implemented in the check_authentication function within changedetectionio/flask_app.py.\nThis flaw enables remote attackers to manipulate authentication processes, potentially leading to unauthorized access to the application's functionality. The impact is significant, as it compromises the confidentiality and integrity of the monitoring service. Given that the vulnerability has been publicly disclosed and the vendor has not responded to outreach, the risk of exploitation by malicious actors is high. No specific complex authentication or privilege requirements are needed to exploit this flaw, as it permits remote access via the network.\nOrganizations relying on affected versions should consider immediate compensatory controls to restrict access to the application, as the lack of a vendor patch necessitates a defensive-in-depth posture to mitigate the risk of unauthorized exploitation.",
"technicalDetails": "The vulnerability resides in the check_authentication function located in changedetectionio/flask_app.py within the changedetection.io application. This function is responsible for verifying user credentials or session tokens before granting access to protected resources. The root cause of the issue is an improper implementation of the authentication logic, which fails to correctly validate or enforce security constraints, leading to a bypass mechanism.\nThe attack flow originates from a remote, unauthenticated attacker who targets the application via the network. By manipulating the inputs or the environment monitored by the check_authentication function, an attacker can trick the application into returning a successful authentication result regardless of the credentials provided. This is typically achieved by leveraging flaws in how the application processes authentication hooks or session parameters, where the function fails to perform strict identity verification.\nDuring exploitation, the attacker interacts with the HTTP-based interfaces of the application. By sending specially crafted requests, the attacker triggers the flawed logic in check_authentication. Because the function does not properly validate the authenticity or integrity of the session or credentials, the application assumes a legitimate state, effectively granting the attacker the permissions associated with an authorized user.\nThe impacted versions include dgtlmoon changedetection.io up to 0.60.7. The vulnerability is characterized by a failure in the authentication hook mechanism, which is intended to serve as a gatekeeper for the application's sensitive monitoring functions. Once the authentication check is bypassed, the attacker achieves post-exploitation access equivalent to that of an authenticated user. Depending on the configuration, this could allow the attacker to view sensitive data, modify monitoring jobs, or potentially interact with the underlying system depending on the application's privileges.\nBecause the exploit is disclosed to the public, the barrier to entry for an attacker is minimal, as they do not need to discover the vulnerability independently. The lack of a vendor response indicates that the vulnerability remains unpatched in the specified versions, necessitating manual intervention by administrators to protect the service from remote, unauthorized access."
}