CVE Feed

    Dashboard / CVE / CVE-2026-59709

    CVE-2026-59709

    Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with valid read-only share tokens can assign or remove tags on victim holdings, corrupting portfolio categorization and reports.

    Published:Jul 7, 2026
    Last Modified:Jul 8, 2026
    EPS:Jul 7, 2026
    EPSS Score:0.002
    CVSS Score:4.3

    Affected Products

    Vendor
    Ghostfol
    Product
    Ghostfolio
    Vendor
    Ghostfolio
    Product
    Ghostfolio

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High