PatchSiren

BookStack CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW BookStack CVE published 2026-09-07

CVE-2026-86285

A vulnerability was detected in BookStack up to 26.05.2, affecting the Attachment Edit Endpoint. The issue allows for improper access controls due to a missing permission check, enabling remote attacks. A patch is available as 4e406c41c4c8060a5795e74c66fb96362e54f400. This vulnerability has been publicly disclosed and may be exploited. Defenders should assess exposure and prioritize patching to prevent un [truncated]