Remote Code Execution Vulnerability in BookStack by BookStackApp
CVE-2026-82450
8.7HIGH
What is CVE-2026-82450?
BookStack versions prior to 26.05.4 are susceptible to a remote code execution vulnerability through the ZIP import functionality. Users granted Import Content and Create Books permissions can upload malicious PHP polyglot files embedded within ZIP archives. This exploitation circumvents the image extension validation, allowing attackers to execute arbitrary PHP code as the uploaded files are stored in the public web root, potentially leading to unauthorized access and execution of commands on the server without authentication.
Affected Version(s)
bookstack 0 < 26.05.4
