LOW
BookStack
CVE published 2026-09-07
CVE-2026-86285
A vulnerability was detected in BookStack up to 26.05.2, affecting the Attachment Edit Endpoint. The issue allows for improper access controls due to a missing permission check, enabling remote attacks. A patch is available as 4e406c41c4c8060a5795e74c66fb96362e54f400. This vulnerability has been publicly disclosed and may be exploited. Defenders should assess exposure and prioritize patching to prevent un [truncated]