PT-2026-92117 · Bookstack · Bookstack

·

CVE-2026-89022

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v4.0

9.1

Critical

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions BookStack versions prior to 26.05.5
Description An authentication bypass exists in the social login implementation. Unauthenticated attackers can sign in as arbitrary users by authenticating through a social provider that shares the same driver id namespace as another provider. This occurs because the handleLoginCallback() function in SocialAuthService fails to include the driver column when querying linked account records, allowing a user ID from one provider to match an account linked to a different provider and bypass credential verification.
Recommendations Update BookStack to version 26.05.5 or later.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89022

Affected Products

Bookstack