PT-2026-86402 · Pixelfed · Pixelfed

·

CVE-2026-86178

·

Published

2026-09-05

·

Updated

2026-09-05

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pixelfed versions prior to 0.12.10
Description Authenticated users can access stories restricted to followers due to a failure to validate follower status in the StoryComposeController react and comment endpoints. By enumerating sequential story IDs and submitting reactions or comments, an attacker can retrieve author information and media URLs of the stories.
Recommendations Update Pixelfed to version 0.12.10 or later. Restrict access to the StoryComposeController react and comment endpoints as a temporary mitigation measure.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86178

Affected Products

Pixelfed