Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-86112

MEDIUM NVD
CVSS Score 5.4
Severity MEDIUM
Published Sep 05, 2026
Vendor unknown

Description

BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can POST to the favorite endpoint with a status ID to create unauthorized interactions, trigger ActivityPub broadcasts, and enumerate private status IDs through response differentiation.

References