Security Advisory

CVE-2026-86112

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-05 09:59:04
Last updated 2026-09-05 09:59:04
Assigner VulnCheck
CVSS score 5.4
State PUBLISHED

Description

BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can POST to the favorite endpoint with a status ID to create unauthorized interactions, trigger ActivityPub broadcasts, and enumerate private status IDs through response differentiation.