<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:dgtlmoon:changedetection_io:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3adgtlmoonchangedetection_io/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 14:36:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3adgtlmoonchangedetection_io/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Authentication in dgtlmoon changedetection.io</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-95271/</link><pubDate>Tue, 22 Sep 2026 14:36:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-95271/</guid><description>CVE-2026-95271 is an improper authentication vulnerability in dgtlmoon changedetection.io versions up to 0.60.7, allowing remote attackers to bypass security via the check_authentication function.</description><content:encoded><![CDATA[<p>A vulnerability has been identified in dgtlmoon changedetection.io versions up to 0.60.7. The issue exists within the check_authentication function located in the changedetectionio/flask_app.py file, which is part of the Authentication Hook component. This vulnerability stems from improper authentication logic, which may allow remote, unauthenticated attackers to bypass intended access controls. The vulnerability has been publicly disclosed with functional exploit code available. The vendor has not provided a patch or response regarding this issue as of the time of disclosure, making it critical for administrators to isolate the application from public access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a remote, unauthenticated attacker to bypass authentication mechanisms, potentially granting unauthorized access to the application's functionality. This could lead to sensitive data exposure, unauthorized modification of monitored URLs, and potential remote control of the changedetection.io instance.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Restrict network access to the changedetection.io instance by placing it behind a reverse proxy or VPN to prevent public access until an official patch is released.</li>
<li>Implement robust authentication at the network perimeter, such as Mutual TLS (mTLS) or OAuth2 via a web application firewall (WAF), to compensate for the vulnerability in the Authentication Hook component.</li>
<li>Monitor application logs for anomalous access patterns or unexpected authentication successes originating from suspicious external IP addresses.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>authentication-bypass</category></item></channel></rss>