Skip to main content
Vulnerability Database/CVE-2026-95271

CVE-2026-95271: changedetection.io Auth Bypass Vulnerability

CVE-2026-95271 is an authentication bypass flaw in changedetection.io versions up to 0.60.7 that allows attackers to circumvent security controls. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-95271 Overview

CVE-2026-95271 is an improper authentication vulnerability in dgtlmoon/changedetection.io versions up to 0.60.7. The flaw resides in the check_authentication function within changedetectionio/flask_app.py, part of the Authentication Hook component. The function performs credential comparison in a non-constant-time manner, exposing the application to timing side-channel analysis [CWE-208 / CWE-287]. Remote attackers can measure response-time differentials to infer valid credential material. The exploit technique has been publicly disclosed. The vendor was contacted before publication but did not respond.

Critical Impact

Remote, unauthenticated attackers can leverage timing discrepancies in the authentication routine to progressively recover credentials and bypass authentication controls on changedetection.io instances.

Affected Products

  • dgtlmoon changedetection.io versions up to and including 0.60.7
  • Deployments exposing the changedetection.io web interface over the network
  • Self-hosted and containerized changedetection.io installations relying on the built-in authentication hook

Discovery Timeline

  • 2026-09-22 - CVE-2026-95271 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-95271

Vulnerability Analysis

The vulnerability affects the check_authentication function in changedetectionio/flask_app.py. This function validates credentials submitted against the changedetection.io Authentication Hook. According to the referenced timing attack analysis, the comparison logic short-circuits on the first mismatched character. That behavior produces measurable variations in response time based on how many leading characters of the supplied secret match the stored value.

An attacker measuring response times across many authentication attempts can statistically infer the correct value one character at a time. This reduces the effective search space from exponential to linear in the length of the secret. Because the comparison occurs inside a network-exposed endpoint, exploitation does not require any prior privilege or user interaction.

Successful exploitation degrades confidentiality, integrity, and availability of the monitored site configurations, notification settings, and stored watch data managed by changedetection.io.

Root Cause

The root cause is the use of a non-constant-time comparison for authentication material [CWE-208: Observable Timing Discrepancy]. Secure credential comparisons must execute in time independent of how many bytes match. The affected code path fails this requirement, allowing side-channel leakage of secret contents.

Attack Vector

Exploitation is performed remotely over the network against the authentication endpoint. The attacker issues a large volume of authentication requests with candidate secrets, records precise response timings, and applies statistical analysis to determine correct byte values. Refer to the public timing attack write-up and the VulDB entry for CVE-2026-95271 for technical specifics.

No verified proof-of-concept code has been reproduced here. Describing the mechanism in prose: the attacker iterates candidate characters at position n, sends authentication requests, and selects the character that produced the highest measured server-side processing latency before advancing to position n+1.

Detection Methods for CVE-2026-95271

Indicators of Compromise

  • High-volume authentication request bursts from a single source or narrow IP range targeting the changedetection.io login endpoint.
  • Sequential authentication attempts where submitted secrets share long common prefixes, consistent with byte-by-byte recovery.
  • Unusual application log patterns showing repeated authentication failures without corresponding lockouts or throttling events.

Detection Strategies

  • Instrument the changedetection.io reverse proxy or WAF to count failed authentication attempts per source and alert on statistically anomalous bursts.
  • Deploy request-timing analytics that flag scripted, uniformly spaced authentication traffic characteristic of side-channel measurement.
  • Correlate authentication failures with source geolocation and user-agent anomalies to distinguish automated probing from legitimate use.

Monitoring Recommendations

  • Forward web server and changedetection.io application logs to a centralized analytics platform for retention and query.
  • Monitor for authentication endpoints receiving traffic outside expected administrator working hours or from unexpected networks.
  • Track EPSS trend data (currently 0.654%) alongside vendor advisories to reassess exposure as exploitation likelihood evolves.

How to Mitigate CVE-2026-95271

Immediate Actions Required

  • Restrict network exposure of changedetection.io administrative endpoints to trusted networks or VPN-only access.
  • Place the application behind a reverse proxy that enforces authentication rate limiting and progressive back-off on failed attempts.
  • Rotate any credentials used with the affected Authentication Hook, especially if the instance has been internet-exposed.

Patch Information

At the time of publication, no fixed version has been published in the NVD entry for CVE-2026-95271. The vendor was contacted but did not respond according to the disclosure record. Monitor the dgtlmoon/changedetection.io repository for releases beyond 0.60.7 that replace the vulnerable comparison logic in check_authentication with a constant-time comparison such as Python's hmac.compare_digest.

Workarounds

  • Front the application with an authenticating reverse proxy (for example, nginx with auth_basic, Traefik forward-auth, or an SSO gateway) so the vulnerable comparison is never reached by untrusted clients.
  • Enforce strict rate limiting (for example, five failed attempts per minute per source) on the authentication endpoint to defeat statistical timing attacks that require large sample sizes.
  • Bind the changedetection.io service to 127.0.0.1 and access it only through an SSH tunnel or private overlay network until a patched release is available.
bash
# Example nginx configuration to rate-limit and front the changedetection.io login endpoint
http {
    limit_req_zone $binary_remote_addr zone=cd_auth:10m rate=5r/m;

    server {
        listen 443 ssl;
        server_name changedetection.example.com;

        location / {
            auth_basic "Restricted";
            auth_basic_user_file /etc/nginx/.htpasswd;
            limit_req zone=cd_auth burst=5 nodelay;
            proxy_pass http://127.0.0.1:5000;
        }
    }
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.