Broken Access Control in BookStack Image Gallery API
CVE-2026-67204

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2026-67204?

In BookStack versions before 26.05.4, a vulnerability has been identified in the Image Gallery API that allows authenticated users to manipulate other users' avatars due to insufficient content-type restrictions. Attackers possessing image-update or image-delete permissions can exploit this weakness by providing a user avatar's ID to the API controller. This allows access to any image type without adhering to the gallery and drawio restrictions set by the web controller. When the uploaded_to field of the avatar matches a page ID that the attacker can access, the authorization check incorrectly passes, permitting the attacker to rename, replace, or delete the target user's avatar without needing user-management permissions.

Affected Version(s)

BookStack 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ByteMe.Red
VulnCheck
.