CVE-2026-46485

Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8.

Scoring

Severity
HIGH
CVSS base score
8.2
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
EPSS probability
0.42%
CWE
CWE-15, CWE-284, CWE-287, CWE-602
Published
2026-07-15
Last modified
2026-07-20

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs