Vulmon Vulnerability Feed@VulmonFeedsPatch
CVE‑2026‑35490 is an authentication bypass flaw in changedetection.io versions older than 0.54.8, and upgrading to 0.54.8 removes the vulnerability.
CVE@CVEnewGeneral
The post references CVE-2026-35490 and a note about a decorator ordering change in changedetection.io, but provides no technical details, exploit code, or mitigation information.
CVEFind.com@CveFindComPatch
The post announces that CVE-2026-35490, a critical Flask decorator ordering issue, has been fixed in changedetection.io version 0.54.8, providing a clear patch without any exploit or active threat discussion.
0day Signal@0dayPublishingDisclosure
The post announces the discovery of CVE-2026-35490, a Flask authentication bypass mistake with a CVSS of 9.8, but it does not provide proof of concept, exploit code, or evidence of active exploitation.
PulsePatch.io@pulsepatchioDisclosure
The post announces CVE-2026-35490, an authentication bypass on changedetection.io, highlighting the issue’s cause and urging users to review access controls and await official patches.
Vulert@vulert_officialPatch
A critical authentication bypass vulnerability (CVE-2026-35490) in changedetection.io exposes sensitive data; users are urged to update immediately to patch the decorator order flaw.