Insecure Direct Object Reference in BookWyrm by BookWyrm Social
CVE-2026-86111

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86111?

The version 0.9.1 of BookWyrm fails to properly validate user visibility permissions when handling the status edit endpoint. Authenticated users can exploit this flaw to access and read private reviews, typically restricted to followers or direct recipients, by simply sequencing through status IDs. This oversight enables attackers to retrieve sensitive content that bypasses intended privacy measures, exposing followers-only and direct-message reviews through the edit interface.

Affected Version(s)

bookwyrm 0 <= 0.9.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.