{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adgtlmoonchangedetection_io/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:dgtlmoon:changedetection_io:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-95271"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["changedetection.io (\u003c 0.60.8)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["dgtlmoon"],"content_html":"\u003cp\u003eA vulnerability has been identified in dgtlmoon changedetection.io versions up to 0.60.7. The issue exists within the check_authentication function located in the changedetectionio/flask_app.py file, which is part of the Authentication Hook component. This vulnerability stems from improper authentication logic, which may allow remote, unauthenticated attackers to bypass intended access controls. The vulnerability has been publicly disclosed with functional exploit code available. The vendor has not provided a patch or response regarding this issue as of the time of disclosure, making it critical for administrators to isolate the application from public access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a remote, unauthenticated attacker to bypass authentication mechanisms, potentially granting unauthorized access to the application's functionality. This could lead to sensitive data exposure, unauthorized modification of monitored URLs, and potential remote control of the changedetection.io instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict network access to the changedetection.io instance by placing it behind a reverse proxy or VPN to prevent public access until an official patch is released.\u003c/li\u003e\n\u003cli\u003eImplement robust authentication at the network perimeter, such as Mutual TLS (mTLS) or OAuth2 via a web application firewall (WAF), to compensate for the vulnerability in the Authentication Hook component.\u003c/li\u003e\n\u003cli\u003eMonitor application logs for anomalous access patterns or unexpected authentication successes originating from suspicious external IP addresses.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-22T14:36:33Z","date_published":"2026-09-22T14:36:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-95271/","summary":"CVE-2026-95271 is an improper authentication vulnerability in dgtlmoon changedetection.io versions up to 0.60.7, allowing remote attackers to bypass security via the check_authentication function.","title":"Improper Authentication in dgtlmoon changedetection.io","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-95271/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:dgtlmoon:changedetection_io:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}