{"id":"CVE-2026-71204","title":"changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.","summary":"changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.","severity":"medium","cvss":6.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L","cwe":["CWE-284"],"published":"2026-08-05","updated":"2026-08-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71204","references":[{"url":"https://github.com/dgtlmoon/changedetection.io","label":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"tags":["nvd","exploit-available"],"epss":0.00254,"epssPercentile":0.17239,"ingestedAt":"2026-08-10T12:39:48.261Z","exploits":{"github":1,"githubRepos":["https://github.com/Nel-droid/CVE-2026-71204-PoC"],"checkedAt":"2026-09-23T07:14:41.569Z"},"exploitAvailable":true,"slug":"CVE-2026-71204","body":"## Overview\n\nchangedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":34.1,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5454,"id":"CVE-2026-71204","ts":1788887284175,"field":"exploit_available","old":"false","new":"true"},{"seq":4337,"id":"CVE-2026-71204","ts":1788886398188,"field":"exploit_available","old":"true","new":"false"},{"seq":3066,"id":"CVE-2026-71204","ts":1788883061369,"field":"exploit_available","old":"false","new":"true"},{"seq":2095,"id":"CVE-2026-71204","ts":1788882466259,"field":"exploit_available","old":"true","new":"false"},{"seq":1161,"id":"CVE-2026-71204","ts":1788881903027,"field":"exploit_available","old":"false","new":"true"}]}