CVE-2026-86112: Bookwyrm-Social Bookwyrm

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can POST to the favorite endpoint with a status ID to create unauthorized interactions, trigger ActivityPub broadcasts, and enumerate private status IDs through response differentiation.

Affected products

Published 2026-09-05. Last modified 2026-09-10.