CVE-2026-86111
Received Received - Intake

BookWyrm Status Edit Permission Bypass Exposes Private Reviews

Vulnerability report for CVE-2026-86111, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: VulnCheck

Description

BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
bookwyrm bookwyrm to 0.9.1 (inc)
bookwyrm bookwyrm 0.9.1
bookwyrm bookwyrm 0.8.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

BookWyrm through version 0.9.1 has a vulnerability where the status edit endpoint does not properly check user permissions for visibility. This allows authenticated attackers to read private content like followers-only or direct-message reviews by guessing sequential status IDs. Attackers can access restricted content through the edit view, bypassing privacy settings.

Impact Analysis

If you use BookWyrm up to version 0.9.1, an attacker with an account could read your private statuses, including followers-only or direct messages, by exploiting this flaw. This could expose sensitive or personal content you intended to keep private.

Compliance Impact

This vulnerability could lead to unauthorized access to private user data, potentially violating privacy regulations like GDPR or HIPAA. Exposure of personal or sensitive information may result in non-compliance with data protection requirements.

Mitigation Strategies

Upgrade BookWyrm to a version later than 0.9.1 where the IDOR vulnerability in the EditStatus endpoint has been patched. Ensure proper authorization checks are implemented to validate user permissions before allowing access to restricted statuses.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86111. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart