在 BookStack 26.05.2 及更早版本中发现一个漏洞。该问题影响了组件“附件编辑端点”中文件 内的函数 。对参数 的操纵会导致访问控制不当(Improper Access Controls)。该攻击可通过远程发起。此漏洞的利用方式(exploit)现已公开,可能被实际利用。修复补丁的提交标识为 。建议应用该补丁以修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | BookStack | 26.05.0 |
cpe:2.3:a:bookstack:bookstack:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86271 | 4.7 MEDIUM | FluentCMS PermissionManager.cs GetAccessible authorization |
| CVE-2026-86289 | 4.3 MEDIUM | Ollama GGUF Decoder gguf.go readGGUFV1String integer overflow |
| CVE-2026-86244 | 4.3 MEDIUM | FastAdmin User Controller User.php login cross site scripting |
No comments yet