SB2026091614 - Incorrect authorization in Firefly III



SB2026091614 - Incorrect authorization in Firefly III

Published: September 16, 2026

Security Bulletin ID SB2026091614
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass an administrative account block.

The vulnerability exists due to incorrect authorization in the API preferences endpoint when setting arbitrary preference names and accessing the email-change confirmation endpoint. A remote user can set the security-sensitive email_change_confirm_token preference to a known value and access the corresponding confirmation URL to bypass an administrative account block.

Exploitation requires an API token obtained before the account is blocked.


Remediation

Install update from vendor's website.