Sploitus

CVE-2026-71203

1 known exploit for CVE-2026-71203

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method carries neither @auth.check_token nor @validate_openapi_request.

Affected products
Changedetection.Io
CVSS 3.1
5.3 MEDIUM
EPSS
0.3% (17th percentile)
Weakness
CWE-306
NVD status
Deferred
Published
2026-08-05
CVE-2026-71203 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-71203

Proof-of-concept code and exploit modules indexed by Sploitus