Description
Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with valid read-only share tokens can assign or remove tags on victim holdings, corrupting portfolio categorization and reports.
Published: 2026-07-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Ghostfolio’s PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint lacks a permission check when processing the Impersonation‑Id header. The missing authorization allows users who hold a read‑only token to assign or remove tags on portfolio holdings, a function intended for privileged accounts. This ability can corrupt portfolio categorization and the resulting financial reports, degrading the integrity and trustworthiness of the data but does not provide direct system compromise.

Affected Systems

The flaw applies to the Ghostfolio portfolio management platform distributed by Ghostfolio. No exact version range is specified, so all releases prior to the application of the corrective patch that reinstates the missing permission validation are considered vulnerable.

Risk and Exploitability

Scored with a CVSS of 5.3, the vulnerability is considered moderate. The EPSS is less than 1%, indicating a low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending a crafted HTTPS PUT request to the tags endpoint, supplying a valid read‑only share token and an Impersonation‑Id header. No additional privileges or system compromise are required, making the attack straightforward for anyone who can obtain a read‑only token.

Generated by OpenCVE AI on July 26, 2026 at 19:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch commit 697ef59e3b58bebc5c21a9e482e4f5643390f316 to re‑establish permission checks on the tags API endpoint.
  • Revoke or rotate any read‑only share tokens that have been exposed beyond their intended recipients.
  • Enforce proper permission validation for requests containing an Impersonation‑Id header, ensuring that only users with appropriate privileges can modify portfolio tags.

Generated by OpenCVE AI on July 26, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Ghostfolio
Ghostfolio ghostfolio
Vendors & Products Ghostfolio
Ghostfolio ghostfolio

Tue, 07 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with valid read-only share tokens can assign or remove tags on victim holdings, corrupting portfolio categorization and reports.
Title Ghostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Permission Check
First Time appeared Ghostfol
Ghostfol ghostfolio
Weaknesses CWE-862
CPEs cpe:2.3:a:ghostfol:ghostfolio:*:*:*:*:*:*:*:*
Vendors & Products Ghostfol
Ghostfol ghostfolio
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ghostfol Ghostfolio
Ghostfolio Ghostfolio
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-20T17:46:02.037Z

Reserved: 2026-07-06T15:31:46.188Z

Link: CVE-2026-59709

cve-icon Vulnrichment

Updated: 2026-07-08T16:49:12.903Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:30:03Z

Weaknesses