Broken Access Control in BookStack Image Gallery API
CVE-2026-67204
5.3MEDIUM
What is CVE-2026-67204?
In BookStack versions before 26.05.4, a vulnerability has been identified in the Image Gallery API that allows authenticated users to manipulate other users' avatars due to insufficient content-type restrictions. Attackers possessing image-update or image-delete permissions can exploit this weakness by providing a user avatar's ID to the API controller. This allows access to any image type without adhering to the gallery and drawio restrictions set by the web controller. When the uploaded_to field of the avatar matches a page ID that the attacker can access, the authorization check incorrectly passes, permitting the attacker to rename, replace, or delete the target user's avatar without needing user-management permissions.
Affected Version(s)
BookStack 0
