BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can POST to the favorite endpoint with a status ID to create unauthorized interactions, trigger ActivityPub broadcasts, and enumerate private status IDs through response differentiation.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 05 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can POST to the favorite endpoint with a status ID to create unauthorized interactions, trigger ActivityPub broadcasts, and enumerate private status IDs through response differentiation. | |
| Title | BookWyrm through 0.9.1 Missing Authorization on the Favorite and Unfavorite Endpoints | |
| First Time appeared |
Joinbookwyrm
Joinbookwyrm bookwyrm |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:joinbookwyrm:bookwyrm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Joinbookwyrm
Joinbookwyrm bookwyrm |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-05T09:59:04.004Z
Reserved: 2026-09-05T01:59:19.567Z
Link: CVE-2026-86112
No data.
Status : Received
Published: 2026-09-05T10:16:42.130
Modified: 2026-09-05T10:16:42.130
Link: CVE-2026-86112
No data.
OpenCVE Enrichment
Updated: 2026-09-05T11:30:05Z
Weaknesses