Incorrect authorization in Firefly III - #VU150157

 

Incorrect authorization in Firefly III - #VU150157

Published: September 16, 2026


Vulnerability identifier: #VU150157
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass an administrative account block.

The vulnerability exists due to incorrect authorization in the API preferences endpoint when setting arbitrary preference names and accessing the email-change confirmation endpoint. A remote user can set the security-sensitive email_change_confirm_token preference to a known value and access the corresponding confirmation URL to bypass an administrative account block.

Exploitation requires an API token obtained before the account is blocked.


Affected software

Firefly III

Remediation

Install security update from vendor's website.

Firefly III - update to 6.6.6

External References

Related Security Bulletins