PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46485 lissy93 CVE debrief

CVE-2026-46485 is a HIGH severity vulnerability in Dashy, a self-hostable personal dashboard. Prior to version 4.0.8, deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality, despite configured permissions. This could lead to unauthorized modification of dashboard configuration and potential service disruption. The issue is fixed in version 4.0.8. Affected administrators and users of Dashy, especially those using OIDC for authentication, should be aware of this vulnerability and take immediate action to update to version 4.0.8 or apply necessary mitigations.

Vendor
lissy93
Product
dashy
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-15
Original CVE updated
2026-07-20
Advisory published
2026-07-15
Advisory updated
2026-07-20

Who should care

Administrators and users of Dashy, especially those using OIDC for authentication, should be aware of this vulnerability and take immediate action to update to version 4.0.8 or apply necessary mitigations. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.

Technical summary

The vulnerability exists in the config-saving functionality of Dashy, allowing unauthorized users to modify the main config.yaml file. This is possible due to inadequate permission checks in the OIDC authentication process. The CVSS score for this vulnerability is 8.2, indicating a HIGH severity level. The vulnerability can be exploited remotely, with no user interaction required. Dashy deployments using OIDC are affected, and the issue is fixed in version 4.0.8.

Defensive priority

High

Recommended defensive actions

  • Update Dashy to version 4.0.8 or later
  • Review and restrict access to the config-saving functionality
  • Monitor dashboard configuration for unauthorized changes
  • Implement additional security measures, such as IP restrictions or two-factor authentication
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-15T19:17:17.657Z and was last modified on 2026-07-20T16:17:01.520Z. The NVD entry is currently Deferred. The vulnerability affects Dashy deployments using OIDC, allowing unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality. The issue is fixed in version 4.0.8. Evidence limits suggest verifying Dashy version and OIDC configuration.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46485 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46485

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46485 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46485

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.