PatchSiren cyber security CVE debrief
CVE-2026-46485 lissy93 CVE debrief
CVE-2026-46485 is a HIGH severity vulnerability in Dashy, a self-hostable personal dashboard. Prior to version 4.0.8, deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality, despite configured permissions. This could lead to unauthorized modification of dashboard configuration and potential service disruption. The issue is fixed in version 4.0.8. Affected administrators and users of Dashy, especially those using OIDC for authentication, should be aware of this vulnerability and take immediate action to update to version 4.0.8 or apply necessary mitigations.
- Vendor
- lissy93
- Product
- dashy
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-15
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-07-15
- Advisory updated
- 2026-07-20
Who should care
Administrators and users of Dashy, especially those using OIDC for authentication, should be aware of this vulnerability and take immediate action to update to version 4.0.8 or apply necessary mitigations. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.
Technical summary
The vulnerability exists in the config-saving functionality of Dashy, allowing unauthorized users to modify the main config.yaml file. This is possible due to inadequate permission checks in the OIDC authentication process. The CVSS score for this vulnerability is 8.2, indicating a HIGH severity level. The vulnerability can be exploited remotely, with no user interaction required. Dashy deployments using OIDC are affected, and the issue is fixed in version 4.0.8.
Defensive priority
High
Recommended defensive actions
- Update Dashy to version 4.0.8 or later
- Review and restrict access to the config-saving functionality
- Monitor dashboard configuration for unauthorized changes
- Implement additional security measures, such as IP restrictions or two-factor authentication
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-15T19:17:17.657Z and was last modified on 2026-07-20T16:17:01.520Z. The NVD entry is currently Deferred. The vulnerability affects Dashy deployments using OIDC, allowing unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality. The issue is fixed in version 4.0.8. Evidence limits suggest verifying Dashy version and OIDC configuration.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T19:17:17.657Z and has not been modified since then. The NVD entry is currently Deferred.