CVE-2026-71204
MEDIUM 6.2EPSS 0.3%
changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.
- CVSS v3.1
- 6.2 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L - EPSS
- 0.25% chance of exploitation in the next 30 days, 17th percentile
- Published
- 2026-08-05
- Updated
- 2026-08-10
Proof-of-concept exploits (1)
- Nel-droid/CVE-2026-71204-PoC0★ · 2026-08-16