Beveiligingsadvies

CVE-2026-86178

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-05 11:01:28
Laatst bijgewerkt 2026-09-08 17:21:02
Toegewezen door VulnCheck
CVSS-score 5.4
Status PUBLISHED

Beschrijving

Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URLs and author information without following the account.