Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 15 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lissy93
Lissy93 dashy |
|
| Vendors & Products |
Lissy93
Lissy93 dashy |
Wed, 15 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8. | |
| Title | Dash: Users can write to config despire permissions (OIDC tested) | |
| Weaknesses | CWE-15 CWE-284 CWE-287 CWE-602 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-20T14:38:24.078Z
Reserved: 2026-05-14T18:06:06.811Z
Link: CVE-2026-46485
No data.
Status : Deferred
Published: 2026-07-15T19:17:17.657
Modified: 2026-07-20T16:17:01.520
Link: CVE-2026-46485
No data.
OpenCVE Enrichment
Updated: 2026-08-01T09:00:04Z