Authentication Bypass in BookStack's Social Login Implementation
CVE-2026-89022
9.1CRITICAL
What is CVE-2026-89022?
A significant vulnerability exists in BookStack's implementation of social login that permits unauthenticated attackers to gain unauthorized access to accounts. This flaw enables attackers to use a user ID from one social provider to authenticate through another provider sharing a common driver ID namespace. Due to inadequate credential verification during the login process, attackers can bypass normal authentication checks, allowing them access to potentially sensitive user accounts.
Affected Version(s)
bookstack 0 < 26.05.5
