CVE-2026-86113
Received Received - Intake

Authorization Bypass in BookWyrm Reading Records

Vulnerability report for CVE-2026-86113, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: VulnCheck

Description

BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite arbitrary users' start dates, finish dates, progress, and progress mode, affecting reading statistics and exported data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bookwyrm bookwyrm 0.9.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

BookWyrm through version 0.9.1 has an authorization bypass flaw in the edit_readthrough function. This allows authenticated users to modify other users' reading records by exploiting sequential ReadThrough IDs. Attackers can change start dates, finish dates, progress, and progress mode of arbitrary users, impacting reading statistics and exported data.

Detection Guidance

To detect this vulnerability, monitor for unauthorized modifications to reading records in BookWyrm. Check for unusual changes to start dates, finish dates, progress, or progress mode in user reading records. Review logs for repeated access attempts to sequential ReadThrough IDs.

Impact Analysis

If you use BookWyrm, an attacker with an account could alter your reading records, making it appear you read books differently than you actually did. This could affect your reading statistics, achievements, or data exported to third parties.

Mitigation Strategies

Immediately update BookWyrm to the latest version beyond 0.9.1. Implement strict ownership checks in the edit_readthrough function to ensure users can only modify their own records. Restrict access to sequential ReadThrough IDs and review user permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86113. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart