High severity8.2NVD Advisory· Published Jul 15, 2026· Updated Jul 20, 2026
CVE-2026-46485
CVE-2026-46485
Description
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.