Authentication Bypass in BookStack's Social Login Implementation
CVE-2026-89022

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-89022?

A significant vulnerability exists in BookStack's implementation of social login that permits unauthenticated attackers to gain unauthorized access to accounts. This flaw enables attackers to use a user ID from one social provider to authenticate through another provider sharing a common driver ID namespace. Due to inadequate credential verification during the login process, attackers can bypass normal authentication checks, allowing them access to potentially sensitive user accounts.

Affected Version(s)

bookstack 0 < 26.05.5

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ada Logics
Google
.