PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-82450 bookstackapp CVE debrief

CVE-2026-82450 is a remote code execution vulnerability in BookStack before version 26.05.4. The vulnerability exists in the portable ZIP import functionality and allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename in the ZIP archive, which is stored in the public web root and executed by unauthenticated requests. This vulnerability has a CVSS score of 8.7 and is rated HIGH. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impact. Administrators and users of BookStack versions before 26.05.4, especially those with Import Content and Create Books permissions, should be aware of this vulnerability and take necessary actions to mitigate the risk. The CVE record was published on 2026-08-29T14:16:37.930Z and has not been modified since then. Details are based on CVE Program and NVD sources.

Vendor
bookstackapp
Product
bookstack
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-29
Original CVE updated
2026-08-29
Advisory published
2026-08-29
Advisory updated
2026-08-29

Who should care

Administrators and users of BookStack versions before 26.05.4, especially those with Import Content and Create Books permissions, should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes applying vendor patches or upgrading to version 26.05.4 or later, restricting permissions to trusted users, and monitoring for suspicious activity. Security teams and vulnerability management teams should also review the vulnerability and implement compensating controls as needed.

Technical summary

CVE-2026-82450 is a remote code execution vulnerability in BookStack before version 26.05.4. The vulnerability exists in the portable ZIP import functionality and allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename in the ZIP archive, which is stored in the public web root and executed by unauthenticated requests. This vulnerability has a CVSS score of 8.7 and is rated HIGH.

Defensive priority

CVE-2026-82450 is rated HIGH with a CVSS score of 8.7; users with Import Content and Create Books permissions in BookStack before 26.05.4 may be vulnerable to remote code execution via book cover upload.

Recommended defensive actions

  • Inventory and verify BookStack version; apply vendor patches or upgrade to version 26.05.4 or later
  • Restrict Import Content and Create Books permissions to trusted users
  • Monitor for suspicious book cover uploads and unauthenticated requests
  • Implement additional security controls, such as web application firewalls and intrusion detection systems
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE-2026-82450 details indicate a remote code execution vulnerability exists in BookStack before version 26.05.4 due to improper validation of uploaded book covers, allowing users with specific permissions to upload malicious PHP files. The vulnerability is rated HIGH with a CVSS score of 8.7. Administrators and users of BookStack versions before 26.05.4, especially those with Import Content and Create Books permissions, should be aware of this vulnerability and take necessary actions to mitigate the risk. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-82450 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-82450

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-82450 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82450

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.