CVE-2026-92815
changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to retrieve responses from restricted network locations.
- Published Sep 16, 2026
- CVSS 8.7 high
- 0.5% chance of exploitation in the next 30 days (EPSS)