Incorrect authorization in Firefly III - #VU150157
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote user to bypass an administrative account block.
The vulnerability exists due to incorrect authorization in the API preferences endpoint when setting arbitrary preference names and accessing the email-change confirmation endpoint. A remote user can set the security-sensitive email_change_confirm_token preference to a known value and access the corresponding confirmation URL to bypass an administrative account block.
Exploitation requires an API token obtained before the account is blocked.