{"id":"CVE-2026-86111","title":"BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs","summary":"BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can acce…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-639"],"vendor":"bookwyrm-social","product":"bookwyrm","affected":["bookwyrm <= 0.9.1"],"published":"2026-09-05","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:05:53.177","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86111","references":[{"url":"https://github.com/bookwyrm-social/bookwyrm","label":"disclosure@vulncheck.com"},{"url":"https://github.com/bookwyrm-social/bookwyrm/blob/v0.9.1/bookwyrm/templates/snippets/create_status/content_field.html","label":"disclosure@vulncheck.com"},{"url":"https://github.com/bookwyrm-social/bookwyrm/blob/v0.9.1/bookwyrm/views/status.py","label":"disclosure@vulncheck.com"},{"url":"https://github.com/geo-chen/oss/blob/main/bookwyrm.md#finding-1-authenticated-idor-in-editstatus-exposes-private-review-comment-and-quotation-content","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/bookwyrm-through-0.9.1-insecure-direct-object-reference-in-editstatus-exposes-followers-only-and-direct-statuses","label":"disclosure@vulncheck.com"},{"url":"https://github.com/geo-chen/oss/blob/main/bookwyrm.md#finding-1-authenticated-idor-in-editstatus-exposes-private-review-comment-and-quotation-content","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T18:07:22.825411Z"},"epss":0.0025,"epssPercentile":0.1671,"ingestedAt":"2026-09-06T07:51:55.706Z","slug":"CVE-2026-86111","body":"## Overview\n\nBookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":8306,"id":"CVE-2026-86111","ts":1788919997162,"field":"exploit_available","old":"false","new":"true"},{"seq":8115,"id":"CVE-2026-86111","ts":1788919284939,"field":"exploit_available","old":"true","new":"false"},{"seq":7924,"id":"CVE-2026-86111","ts":1788916358499,"field":"exploit_available","old":"false","new":"true"},{"seq":7733,"id":"CVE-2026-86111","ts":1788915302191,"field":"exploit_available","old":"true","new":"false"},{"seq":7542,"id":"CVE-2026-86111","ts":1788912718896,"field":"exploit_available","old":"false","new":"true"},{"seq":7351,"id":"CVE-2026-86111","ts":1788911334986,"field":"exploit_available","old":"true","new":"false"},{"seq":7155,"id":"CVE-2026-86111","ts":1788909080451,"field":"exploit_available","old":"false","new":"true"},{"seq":6967,"id":"CVE-2026-86111","ts":1788907392423,"field":"exploit_available","old":"true","new":"false"},{"seq":6769,"id":"CVE-2026-86111","ts":1788905446275,"field":"exploit_available","old":"false","new":"true"},{"seq":6587,"id":"CVE-2026-86111","ts":1788903460473,"field":"exploit_available","old":"true","new":"false"},{"seq":6373,"id":"CVE-2026-86111","ts":1788901812280,"field":"exploit_available","old":"false","new":"true"},{"seq":6203,"id":"CVE-2026-86111","ts":1788899562742,"field":"exploit_available","old":"true","new":"false"},{"seq":5966,"id":"CVE-2026-86111","ts":1788898181189,"field":"exploit_available","old":"false","new":"true"},{"seq":5855,"id":"CVE-2026-86111","ts":1788895711471,"field":"exploit_available","old":"true","new":"false"},{"seq":5779,"id":"CVE-2026-86111","ts":1788894573194,"field":"exploit_available","old":"false","new":"true"}]}