Description
BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.
Published: 2026-09-05
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Bookwyrm-social
Bookwyrm-social bookwyrm
Vendors & Products Bookwyrm-social
Bookwyrm-social bookwyrm

Sat, 05 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.
Title BookWyrm through 0.9.1 Insecure Direct Object Reference in EditStatus Exposes Followers-Only and Direct Statuses
First Time appeared Joinbookwyrm
Joinbookwyrm bookwyrm
Weaknesses CWE-639
CPEs cpe:2.3:a:joinbookwyrm:bookwyrm:*:*:*:*:*:*:*:*
Vendors & Products Joinbookwyrm
Joinbookwyrm bookwyrm
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Bookwyrm-social Bookwyrm
Joinbookwyrm Bookwyrm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-08T18:08:07.525Z

Reserved: 2026-09-05T01:59:19.212Z

Link: CVE-2026-86111

cve-icon Vulnrichment

Updated: 2026-09-08T18:07:53.067Z

cve-icon NVD

Status : Deferred

Published: 2026-09-05T10:16:40.963

Modified: 2026-09-08T20:05:53.177

Link: CVE-2026-86111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T08:25:26Z

Weaknesses