CVE-2026-59709 Details
Description
Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with valid read-only share tokens can assign or remove tags on victim holdings, corrupting portfolio categorization and reports.
A vulnerability exists in Ghostfolio's API, specifically in the PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint. This vulnerability arises because the endpoint does not properly verify the Access.permissions field when handling the Impersonation-Id header. As a result, individuals with read-only access can manipulate portfolio holding tags. Attackers armed with valid read-only share tokens can add or remove tags on behalf of victims, disrupting portfolio organization and reporting.
Users can update to Ghostfolio version 3.6.1 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 7, 2026CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ghostfolio/ghostfolio/issues/7196 | CISA-ADP | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/ghostfolio/ghostfolio | [email protected] | Vendor |
| https://github.com/ghostfolio/ghostfolio/commit/697ef59e3b58bebc5c21a9e482e4f5643390f316 | [email protected] | Source CodeVendor |
| https://github.com/ghostfolio/ghostfolio/issues/7196 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/ghostfolio-unauthorized-portfolio-holding-tag-modification-via-missing-permission-check | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ghostfolio | <= 3.6.0 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | [email protected] |
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | CVE Modified | [email protected] |
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 7, 2026 | New CVE Received | [email protected] |
Volerion