changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.
History

Mon, 10 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update(). Because WTForms represents an unchecked checkbox as False rather than 'unchanged', and only the 'password' field is special-cased against this problem, a POST to /settings that omits the api_access_token_enabled field (e.g. a minimal scripted request) silently disables API key enforcement for the entire REST API, exposing the full watch list, history, and configuration to unauthenticated requests. changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.

Mon, 10 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title changedetection.io: Omitted Checkbox in /settings Save Silently Disables API Key Enforcement changedetection.io - Omitted Checkbox in /settings Save Silently Disables API Key Enforcement

Thu, 06 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Dgtlmoon
Dgtlmoon changedetection.io
Vendors & Products Dgtlmoon
Dgtlmoon changedetection.io

Wed, 05 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update(). Because WTForms represents an unchecked checkbox as False rather than 'unchanged', and only the 'password' field is special-cased against this problem, a POST to /settings that omits the api_access_token_enabled field (e.g. a minimal scripted request) silently disables API key enforcement for the entire REST API, exposing the full watch list, history, and configuration to unauthenticated requests.
Title changedetection.io: Omitted Checkbox in /settings Save Silently Disables API Key Enforcement
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TuranSec

Published: 2026-08-05T06:59:00.078Z

Updated: 2026-08-10T11:45:03.177Z

Reserved: 2026-08-05T06:56:15.799Z

Link: CVE-2026-71204

cve-icon Vulnrichment

Updated: 2026-08-05T13:16:04.776Z

cve-icon NVD

Status : Deferred

Published: 2026-08-05T08:16:42.327

Modified: 2026-08-28T18:51:39.823

Link: CVE-2026-71204

cve-icon Redhat

No data.