Beveiligingsadvies

CVE-2026-86111

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-05 09:59:03
Laatst bijgewerkt 2026-09-08 18:08:07
Toegewezen door VulnCheck
CVSS-score 7.1
Status PUBLISHED

Beschrijving

BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.