CVE-2026-86111
BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.
- Published Sep 5, 2026
- CVSS 7.1 high
- 0.4% chance of exploitation in the next 30 days (EPSS)