CVE-2026-86112

Source
https://cve.org/CVERecord?id=CVE-2026-86112
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86112.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86112
Published
2026-09-05T09:59:04.004Z
Modified
2026-09-07T03:45:29.927348049Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
BookWyrm through 0.9.1 Missing Authorization on the Favorite and Unfavorite Endpoints
Details

BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can POST to the favorite endpoint with a status ID to create unauthorized interactions, trigger ActivityPub broadcasts, and enumerate private status IDs through response differentiation.

Database specific
{
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86112.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/bookwyrm-social/bookwyrm

Affected ranges

Type
GIT
Repo
https://github.com/bookwyrm-social/bookwyrm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.9.1"
        },
        {
            "fixed": "0.9.1"
        }
    ]
}

Affected versions

0.*
0.4.2
v0.*
v0.3.0
v0.3.3
v0.3.4
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4
v0.5.5
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.8.6
v0.8.7
v0.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86112.json"