CVE-2026-92815 Overview
CVE-2026-92815 is a Server-Side Request Forgery (SSRF) vulnerability in changedetection.io through version 0.60.6. The flaw resides in the browser steps feature, specifically the Goto URL action. The application enforces SSRF protections on the primary watch URL but omits equivalent validation on browser step actions. Unauthenticated attackers can supply arbitrary internal URLs through the optional_value parameter and receive responses from restricted network locations. This exposes internal services, cloud metadata endpoints, and other resources that should be unreachable from external networks.
Critical Impact
Unauthenticated attackers can reach internal-only services, cloud instance metadata, and administrative endpoints by abusing the browser step Goto URL action to bypass the SSRF guard applied elsewhere in the application.
Affected Products
- changedetection.io through version 0.60.6
- Deployments exposing the browser steps feature
- Self-hosted and container-based installations running vulnerable releases
Discovery Timeline
- 2026-09-16 - CVE-2026-92815 published to the National Vulnerability Database
- 2026-09-16 - Last updated in NVD database
Technical Details for CVE-2026-92815
Vulnerability Analysis
changedetection.io is a change-monitoring tool that fetches web resources on a schedule and alerts on differences. To handle sites requiring interaction, it exposes a browser steps feature that scripts actions such as clicks, form input, and navigation. The Goto URL action accepts a URL through the optional_value parameter and instructs the headless browser to navigate to it.
The application validates the main watch URL against an SSRF guard that blocks private, loopback, and link-local addresses. That guard is not invoked when browser step actions execute. As a result, the Goto URL action becomes an unauthenticated SSRF primitive that reuses the server's outbound network position [CWE-918].
Root Cause
The root cause is inconsistent enforcement of URL validation across code paths. The SSRF guard is applied only to the primary watch URL processing pipeline. Browser step handlers in changedetectionio/browser_steps/browser_steps.py accept URL input from optional_value and pass it to the headless browser without invoking the same allowlist or address-family checks.
Attack Vector
Exploitation is network-based and does not require authentication or user interaction. An attacker submits a browser step configuration containing a Goto URL action targeting an internal endpoint such as http://127.0.0.1:8080/admin, http://169.254.169.254/latest/meta-data/, or a private RFC1918 host. The headless browser retrieves the resource, and response content or side effects are returned to the attacker. The vulnerability enables reconnaissance of internal networks, retrieval of cloud provider metadata credentials, and interaction with unauthenticated internal services.
See the GitHub SSRF vulnerability finding and the vulnerable code region in browser_steps.py lines 182-192 for technical specifics.
Detection Methods for CVE-2026-92815
Indicators of Compromise
- Outbound HTTP requests from the changedetection.io process to RFC1918 addresses, 127.0.0.0/8, or 169.254.169.254
- Browser step configurations containing Goto URL actions with internal or loopback destinations in optional_value
- Unexpected access log entries on internal services originating from the changedetection.io host
- Cloud audit events showing instance metadata service (IMDS) queries from the application host
Detection Strategies
- Inspect stored watch and browser step configurations for URLs targeting private, loopback, or metadata address ranges
- Enable egress logging on the host running changedetection.io and alert on connections to non-public destinations
- Correlate headless browser process activity with connections to sensitive internal endpoints
Monitoring Recommendations
- Monitor process-level network telemetry from the changedetection.io container or service account for anomalous internal traffic
- Alert on IMDS access from workloads that do not require it, or enforce IMDSv2 with hop-limit restrictions
- Track configuration changes to watches and browser steps through file integrity or application audit logs
How to Mitigate CVE-2026-92815
Immediate Actions Required
- Upgrade changedetection.io to a version later than 0.60.6 once a patched release is available
- Restrict outbound network access from the changedetection.io host to only the destinations required for monitoring
- Place the application behind authentication and prevent unauthenticated access to configuration endpoints
- Block access to cloud metadata endpoints from the workload, or enforce IMDSv2 with a hop limit of 1
Patch Information
At the time of publication, monitor the changedetection.io GitHub repository and the VulnCheck security advisory for release notes addressing the SSRF in browser steps. Apply the fixed version as soon as it is published.
Workarounds
- Disable the browser steps feature if it is not required for monitored watches
- Deploy the application in a network segment with strict egress filtering that denies traffic to internal ranges and metadata IPs
- Route outbound traffic through a filtering proxy that rejects requests to private, loopback, and link-local destinations
- Enforce network policies at the container or pod level to block traffic to 169.254.169.254 and RFC1918 ranges
# Example egress restriction using iptables on the application host
iptables -A OUTPUT -m owner --uid-owner changedetection -d 169.254.169.254 -j REJECT
iptables -A OUTPUT -m owner --uid-owner changedetection -d 10.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner changedetection -d 172.16.0.0/12 -j REJECT
iptables -A OUTPUT -m owner --uid-owner changedetection -d 192.168.0.0/16 -j REJECT
iptables -A OUTPUT -m owner --uid-owner changedetection -d 127.0.0.0/8 -j REJECT
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.