CVE-2026-59708 HIGH

CVE-2026-59708: Ghostfolio - Unauthorized Portfolio Data Exposure via Public Endpoint

Vendor Ghostfolio
Product ghostfolio
Weakness CWE-862 · Missing authorization
Published July 7, 2026
Last update July 20, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve sensitive portfolio information including holdings, quantities, buy prices, and performance metrics without authentication.

Key dates

02Disclosure timeline

July 7, 2026 CVE published
July 20, 2026 Record updated

Related vulnerabilities

04Related CVE