PatchSiren cyber security CVE debrief
CVE-2026-5484 BookStackApp CVE debrief
A weakness has been identified in BookStackApp BookStack up to 26.03, specifically in the chapterToMarkdown function of the ExportFormatter.php file. This weakness can lead to improper access controls when the pages argument is manipulated. The vulnerability can be exploited remotely, and a public exploit is available. Upgrading to version 26.03.1 addresses this issue, which was patched with 8a59895ba063040cc8dafd82e94024c406df3d04. The affected component is BookStackApp BookStack, and the vulnerability class is related to improper access controls. The likely operational impact is medium, given the availability of a public exploit.
- Vendor
- BookStackApp
- Product
- BookStack
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-20
Who should care
Users of BookStackApp BookStack up to version 26.03 should be aware of this weakness and take steps to upgrade to version 26.03.1 or later to mitigate the vulnerability. This involves verifying the presence of affected BookStackApp BookStack deployments, reviewing access controls for the ExportFormatter.php file, and monitoring for suspicious activity related to chapter exports. Additionally, defenders should consider compensating controls, such as restricting access to the ExportFormatter.php file, for exposed systems until remediation can be verified. Asset inventory and vulnerability management processes should be updated to reflect this issue and track exceptions during remediation efforts.
Technical summary
The chapterToMarkdown function in ExportFormatter.php has a weakness that allows for improper access controls when the pages argument is manipulated. This can be exploited remotely, and a public exploit is available. The issue is addressed in version 26.03.1 with patch 8a59895ba063040cc8dafd82e94024c406df3d04. The affected component is BookStackApp BookStack, and the vulnerability class is related to improper access controls. The likely operational impact is medium, given the availability of a public exploit. Defenders should verify the presence of affected BookStackApp BookStack deployments and review access controls for the ExportFormatter.php file.
Defensive priority
Medium priority due to the availability of a public exploit and the potential for remote exploitation. Defenders should verify the presence of affected BookStackApp BookStack deployments and review access controls for the ExportFormatter.php file. Monitoring for suspicious activity related to chapter exports is also recommended while awaiting or implementing remediation efforts. Compensating controls, such as restricting access to the ExportFormatter.php file, should be considered for exposed systems until remediation can be verified. Asset inventory and vulnerability management processes should be updated to reflect this issue and track exceptions during remediation efforts. Rollback change windows may be necessary if issues arise during patch application. Source tracking and review of relevant logs are crucial for detecting potential exploitation attempts. Review and restrict access to the ExportFormatter.php file, and monitor for suspicious activity related to chapter exports. Consider compensating controls for exposed systems while remediation is scheduled and verified. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Review compensating controls for exposed systems while remediation is scheduled and verified. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Review compensating controls for exposed systems while remediation is scheduled and verified. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Track
Recommended defensive actions
- Upgrade BookStackApp BookStack to version 26.03.1 or later
- Apply patch 8a59895ba063040cc8dafd82e94024c406df3d04
- Review and restrict access to the ExportFormatter.php file
- Monitor for suspicious activity related to chapter exports
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record was published on 2026-04-03T20:16:05.347Z and last modified on 2026-07-20T20:10:00.110Z. The NVD entry is currently Deferred. The weakness is in the chapterToMarkdown function of ExportFormatter.php in BookStackApp BookStack up to 26.03. This function can lead to improper access controls when the pages argument is manipulated. The vulnerability can be exploited remotely, and a public exploit is available. Upgrading to version 26.03.1 addresses this issue, which was patched with 8a59895ba063040cc8dafd82e94024c406df3d04. Evidence limits suggest that additional details may exist but are not verified.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T20:16:05.347Z and has not been modified since then. The NVD entry is currently Deferred.