CVE-2026-46485 Details
Description
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8.
A vulnerability in Dashy, a self-hostable personal dashboard, prior to version 4.0.8, allows unauthenticated users or non-admin authenticated users to make unauthorized changes to the main configuration file (config.yaml) via the dashboard's config-saving feature. This issue arises in deployments using OpenID Connect (OIDC) for authentication, where configured permissions are not properly enforced. As a result, unauthorized modifications to the dashboard configuration can be made, potentially disrupting the service.
Users can update to Dashy version 4.0.8, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 15, 2026CISA-ADP
Assessed Jul 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/lissy93/dashy/security/advisories/GHSA-vjj9-fmvr-6h3p | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/lissy93/dashy/releases/tag/4.0.8 | [email protected] | Release NotesVendor |
| https://github.com/lissy93/dashy/security/advisories/GHSA-vjj9-fmvr-6h3p | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-15 | External Control of System or Configuration Setting | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
| CWE-287 | Improper Authentication | [email protected] |
| CWE-602 | Client-Side Enforcement of Server-Side Security | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Dashy | <= 3.2.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |
Volerion