OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-95271

HIGH · CVSS 7.3 EPSS 0.65% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A vulnerability exists in the Authentication Hook of changedetection.io versions up to 0.60.7, specifically within the check_authentication function, allowing for improper authentication. This flaw can be exploited remotely, potentially enabling unauthorized access to sensitive data or system functions. Organizations using this software should prioritize remediation to mitigate the risk of exploitation, especially given the lack of vendor response to the disclosure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-95271
Severity
HIGH
CVSS
7.3
EPSS
0.65%

Original NVD Description

A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.