MEDIUMVulnerability
CVE-2026-71204
changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.
Properties
- severity
- MEDIUM
- score
- 6.2
- cve_id
- CVE-2026-71204
- vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L
- published_at
- 2026-08-05T08:16:42.327
- last_modified
- 2026-08-28T18:51:39.823
Related Entities (2)
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Improper Access Control
Explore deeper with Ninja Signal's threat intelligence graph