Unrated severityNVD Advisory· Published Jul 7, 2026· Updated Jul 20, 2026
Ghostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Permission Check
CVE-2026-59709
Description
Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with valid read-only share tokens can assign or remove tags on victim holdings, corrupting portfolio categorization and reports.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.