CVE-2026-86113

Source
https://cve.org/CVERecord?id=CVE-2026-86113
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86113.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86113
Published
2026-09-05T09:59:04.683Z
Modified
2026-09-07T03:45:34.314362508Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
BookWyrm through 0.9.1 Insecure Direct Object Reference in edit-readthrough Allows Tampering with Other Users' Reading Records
Details

BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite arbitrary users' start dates, finish dates, progress, and progress mode, affecting reading statistics and exported data.

Database specific
{
    "cwe_ids": [
        "CWE-639"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86113.json"
}
References

Affected packages

Git / github.com/bookwyrm-social/bookwyrm

Affected ranges

Type
GIT
Repo
https://github.com/bookwyrm-social/bookwyrm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.9.1"
        },
        {
            "fixed": "0.9.1"
        }
    ]
}

Affected versions

0.*
0.4.2
v0.*
v0.3.0
v0.3.3
v0.3.4
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4
v0.5.5
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.8.6
v0.8.7
v0.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86113.json"