Security Advisory

CVE-2026-86178

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-05 11:01:28
Last updated 2026-09-08 17:21:02
Assigner VulnCheck
CVSS score 5.4
State PUBLISHED

Description

Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URLs and author information without following the account.