BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-05 10:16
Updated : 2026-09-08 20:05
NVD link : CVE-2026-86111
Mitre link : CVE-2026-86111
CVE.ORG link : CVE-2026-86111
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
