PT-2026-92117 · Bookstack · Bookstack
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
BookStack versions prior to 26.05.5
Description
An authentication bypass exists in the social login implementation. Unauthenticated attackers can sign in as arbitrary users by authenticating through a social provider that shares the same
driver id namespace as another provider. This occurs because the handleLoginCallback() function in SocialAuthService fails to include the driver column when querying linked account records, allowing a user ID from one provider to match an account linked to a different provider and bypass credential verification.Recommendations
Update BookStack to version 26.05.5 or later.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bookstack