VYPR
Unrated severityNVD Advisory· Published Jul 7, 2026· Updated Jul 20, 2026

Ghostfolio - Unauthorized Portfolio Data Exposure via Public Endpoint

CVE-2026-59708

Description

The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve sensitive portfolio information including holdings, quantities, buy prices, and performance metrics without authentication.

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.