CVE-2026-27696Disclosure(webtechnologies / changedetection)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch webtechnologies changedetection systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side Request Forgery (SSRF) because the URL validation function `is_safe_valid_url()` does not validate the resolved IP address of watch URLs against private, loopback, or link-local address ranges. An authenticated user (or any user when no password is configured, which is the default) can add a watch for internal network URLs. The application fetches these URLs server-side, stores the response content, and makes it viewable through the web UI — enabling full data exfiltration from internal services. Version 0.54.1 contains a fix for the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • changedetection

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-25); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
changedetection

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-25: 4Mentions · 2026-02-27: 1Mentions · 2026-03-02: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-25: 4Technical Details · 2026-02-27: 1Technical Details · 2026-03-02: 102-2502-2703-02
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-254
Disclosure3Patch1
2026-02-271
Disclosure1
2026-03-021
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27696 (CVSS:8.6, HIGH) is Analyzed. http://changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, http://changedetection.io..https://nvd.nist.gov/vuln/detail/CVE-2026-27696 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-27696 with a high CVSS score and affected versions, but provides no PoC, exploit, or patch details.

    0000033
    173 followersView on X
  • Carl Sampson@chs
    Disclosure

    New post: CVE-2026-27696 — SSRF in http://changedetection.io via URL validation bypass. Default installs have no auth, and the server will happily fetch your AWS metadata endpoint. Root cause, attack scenario, and the TOCTOU problem most URL validators miss. https://chs.us/2026/02/ssrf-changedetection-cve-2026-27696/

    Post summary

    A newly disclosed SSRF vulnerability (CVE‑2026‑27696) in changedetection.io allows unauthenticated servers to retrieve AWS metadata through URL validation bypass, underscoring a TOCTOU flaw.

    0000054
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27696 Server-Side Request Forgery in http://changedetection.io Allows Internal Networ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27696 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new SSRF vulnerability (CVE-2026-27696) affecting changedetection.io has been disclosed, with details available via Vulmon links.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27696 http://changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, http://changedetection.io is vulnerable to Server-Side Request Forgery … https://www.cve.org/CVERecord?id=CVE-2026-27696

    Post summary

    The post announces that versions of changedetection.io prior to 0.54.1 are vulnerable to Server‑Side Request Forgery, referencing the CVE record.

    0000097
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27696: HIGH] Vulnerable to SSRF, http://changedetection.io prior to 0.54.1 allows unauthorized data exfiltration from internal services. Update to version 0.54.1 to address this issue.#cve,CVE-2026-27696,#cybersecurity https://cvefind.com/CVE-2026-27696

    Post summary

    The post highlights a high‑severity SSRF flaw in changedetection.io versions prior to 0.54.1 and recommends updating to 0.54.1 to mitigate the vulnerability.

    0000045
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27696** pertains to a Server-Side Request Forgery (SSRF) vulnerability present in **http://changedetection.io** versions prior to **0.54.1**. The core issue stems from inadequate URL validation, specifically the `is_safe_valid_url()` function, which fails to verify the resolved IP addresses of user-supplied URLs against private, loopback, or link-local address ranges. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-27696

    Post summary

    The post announces a Server‑Side Request Forgery vulnerability (CVE‑2026‑27696) in changedetection.io versions before 0.54.1, detailing the flaw in URL validation and the affected function.

    0000039
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwebtechnologieschangedetection---

Explore more