CVE-2026-46485 HIGH

CVE-2026-46485: Dash: Users can write to config despire permissions (OIDC tested)

Vendor Lissy93
Product dashy
Weakness CWE-15
Published July 15, 2026
Last update July 20, 2026

CVSS base score

8.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

What the vulnerability does

01Description

Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8.

Key dates

02Disclosure timeline

July 15, 2026 CVE published
July 20, 2026 Record updated