PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46485 lissy93 CVE debrief

CVE-2026-46485 is a HIGH severity vulnerability in Dashy, a self-hostable personal dashboard. Prior to version 4.0.8, deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality, despite configured permissions. This could lead to unauthorized modification of dashboard configuration and potential service disruption. The issue is fixed in version 4.0.8. Affected administrators and users of Dashy, especially those using OIDC for authentication, should be aware of this vulnerability and take immediate action to update to version 4.0.8 or apply necessary mitigations.

Vendor
lissy93
Product
dashy
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-15
Original CVE updated
2026-07-20
Advisory published
2026-07-15
Advisory updated
2026-07-20

Who should care

Administrators and users of Dashy, especially those using OIDC for authentication, should be aware of this vulnerability and take immediate action to update to version 4.0.8 or apply necessary mitigations. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.

Technical summary

The vulnerability exists in the config-saving functionality of Dashy, allowing unauthorized users to modify the main config.yaml file. This is possible due to inadequate permission checks in the OIDC authentication process. The CVSS score for this vulnerability is 8.2, indicating a HIGH severity level. The vulnerability can be exploited remotely, with no user interaction required. Dashy deployments using OIDC are affected, and the issue is fixed in version 4.0.8.

Defensive priority

High

Recommended defensive actions

  • Update Dashy to version 4.0.8 or later
  • Review and restrict access to the config-saving functionality
  • Monitor dashboard configuration for unauthorized changes
  • Implement additional security measures, such as IP restrictions or two-factor authentication
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-15T19:17:17.657Z and was last modified on 2026-07-20T16:17:01.520Z. The NVD entry is currently Deferred. The vulnerability affects Dashy deployments using OIDC, allowing unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality. The issue is fixed in version 4.0.8. Evidence limits suggest verifying Dashy version and OIDC configuration.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T19:17:17.657Z and has not been modified since then. The NVD entry is currently Deferred.