CVE-2024-36676: Bookstackapp Bookstack

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms.

Affected products

Published 2024-07-09. Last modified 2026-06-17.