Vulnerability Description
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/lissy93/dashy/releases/tag/4.0.8
- https://github.com/lissy93/dashy/security/advisories/GHSA-vjj9-fmvr-6h3p
- https://github.com/lissy93/dashy/security/advisories/GHSA-vjj9-fmvr-6h3p
FAQ
What is CVE-2026-46485?
CVE-2026-46485 is a vulnerability with a CVSS score of 8.2 (HIGH). Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml thro...
How severe is CVE-2026-46485?
CVE-2026-46485 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-46485?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.