CVE-2026-61463: Go-Shiori Shiori
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted PATCH request with owner: true, then re-authenticate to obtain an admin JWT token granting full system access.
Affected products
- Go-Shiori Shiori
Published 2026-07-13. Last modified 2026-07-13.