Unrated severityNVD Advisory· Published Jul 7, 2026· Updated Jul 20, 2026
Ghostfolio - Unauthorized Portfolio Data Exposure via Public Endpoint
CVE-2026-59708
Description
The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve sensitive portfolio information including holdings, quantities, buy prices, and performance metrics without authentication.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.