Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bookstackapp
Bookstackapp bookstack |
|
| Vendors & Products |
Bookstackapp
Bookstackapp bookstack |
|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints. Attackers can supply a user avatar's ID to the API controller, which loads any image type without the web controller's gallery and drawio restrictions, and when the avatar's uploaded_to field matches a page ID accessible to the attacker, the authorization check passes allowing the attacker to rename, replace, or delete the target user's avatar without requiring user-management permission. | |
| Title | BookStack < 26.05.4 Broken Access Control via Image Gallery API | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T17:20:18.693Z
Reserved: 2026-07-28T16:06:49.775Z
Link: CVE-2026-67204
Updated: 2026-08-24T17:20:12.218Z
Status : Received
Published: 2026-08-24T16:17:17.790
Modified: 2026-08-24T18:17:01.400
Link: CVE-2026-67204
No data.
OpenCVE Enrichment
Updated: 2026-08-24T18:15:06Z