Authorization Bypass Vulnerability in BookWyrm Affects Reading Records
CVE-2026-86113
7.1HIGH
What is CVE-2026-86113?
An authorization bypass vulnerability exists in the BookWyrm application through version 0.9.1, specifically in the edit_readthrough function. This flaw permits authenticated users to manipulate other users' reading entries by exploiting sequential ReadThrough IDs. As a consequence, it enables attackers to alter crucial reading metrics such as start dates, finish dates, progress levels, and modes, thereby compromising the integrity of reading statistics and any exported data.
Affected Version(s)
bookwyrm 0 <= 0.9.1
