CVE-2026-71204

changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-05 08:16

Updated : 2026-08-28 18:51


NVD link : CVE-2026-71204

Mitre link : CVE-2026-71204

CVE.ORG link : CVE-2026-71204


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control