Remote Code Execution Vulnerability in BookStack by BookStackApp
CVE-2026-82450

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
29 August 2026

What is CVE-2026-82450?

BookStack versions prior to 26.05.4 are susceptible to a remote code execution vulnerability through the ZIP import functionality. Users granted Import Content and Create Books permissions can upload malicious PHP polyglot files embedded within ZIP archives. This exploitation circumvents the image extension validation, allowing attackers to execute arbitrary PHP code as the uploaded files are stored in the public web root, potentially leading to unauthorized access and execution of commands on the server without authentication.

Affected Version(s)

bookstack 0 < 26.05.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Submersion.ai Security Research Team
.