SB2026091614 - Incorrect authorization in Firefly III
Published: September 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass an administrative account block.
The vulnerability exists due to incorrect authorization in the API preferences endpoint when setting arbitrary preference names and accessing the email-change confirmation endpoint. A remote user can set the security-sensitive email_change_confirm_token preference to a known value and access the corresponding confirmation URL to bypass an administrative account block.
Exploitation requires an API token obtained before the account is blocked.
Remediation
Install update from vendor's website.