CVE-2026-35490Patch(webtechnologies / changedetection)

LOWCVSS 9.8 · CRITICAL

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch webtechnologies changedetection systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. In Flask, @route() must be the outermost decorator because it registers the function it receives. When the order is reversed, @route() registers the original undecorated function, and the auth wrapper is never in the call chain. This silently disables authentication on these routes. This vulnerability is fixed in 0.54.8.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • changedetection

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 6 total mentions across 1 day

Affected systems

Products
changedetection

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-04-07: 6Patch / Workaround · 2026-04-07: 4Technical Details · 2026-04-07: 504-07
Signal classification3 categories
Patch
350.0%
Disclosure
233.3%
General
116.7%
Referenced assets7 URLs
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2026-35490 Authentication Bypass in http://changedetection.io Prior to Version 0.54.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35490

    Post summary

    CVE‑2026‑35490 is an authentication bypass flaw in changedetection.io versions older than 0.54.8, and upgrading to 0.54.8 removes the vulnerability.

    0000068
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-35490 http://changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @bluepr… https://www.cve.org/CVERecord?id=CVE-2026-35490

    Post summary

    The post references CVE-2026-35490 and a note about a decorator ordering change in changedetection.io, but provides no technical details, exploit code, or mitigation information.

    00000131
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-35490: CRITICAL] Vulnerability fixed in http://changedetection.io v0.54.8--@route() must be outermost for proper function registration. Ensure correct decorators order in Flask to maintain authentication ...#cve,CVE-2026-35490,#cybersecurity https://cvefind.com/CVE-2026-35490

    Post summary

    The post announces that CVE-2026-35490, a critical Flask decorator ordering issue, has been fixed in changedetection.io version 0.54.8, providing a clear patch without any exploit or active threat discussion.

    0000043
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-35490: http://changedetection.io has an Authen... Flask decorator ordering mistake turns auth bypass into a 9.8 CVSS gift - @route() registered the naked function, auth ... https://zerodaysignal.com/vulnerability/CVE-2026-35490 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces the discovery of CVE-2026-35490, a Flask authentication bypass mistake with a CVSS of 9.8, but it does not provide proof of concept, exploit code, or evidence of active exploitation.

    0000060
    204 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An authentication bypass vulnerability (CVE-2026-35490) affects `http://changedetection.io` via decorator ordering. Review access controls and monitor for official patches. #AuthBypass #Security https://www.pulsepatch.io/posts/cve-2026-35490-changedetection-authentication-bypass

    Post summary

    The post announces CVE-2026-35490, an authentication bypass on changedetection.io, highlighting the issue’s cause and urging users to review access controls and await official patches.

    0000034
    11 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Critical http://changedetection.io flaw: CVE-2026-35490 An authentication bypass issue could expose sensitive data to unauthorized access. Update now and fix the decorator order. 🔗 https://vulert.com/vuln-db/CVE-2026-35490 #CyberSecurity #changedetectionio #CVE202635490 #Vulert https://t.co/fW3YDX6AA5

    Post summary

    A critical authentication bypass vulnerability (CVE-2026-35490) in changedetection.io exposes sensitive data; users are urged to update immediately to patch the decorator order flaw.

    0000033
    124 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwebtechnologieschangedetection---

Explore more