Security Advisory
CVE-2026-46485
8.2
HIGH
Vulnerability Description
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8.
Published Date
July 15, 2026
Official Source
NIST NVD Advisory