Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-82450: BookStack lets attackers run code via ZIP upload
CVE-2026-82450 · published 5 days ago
Summary
Versions of BookStack released before 26.05.4 let people who can add books and import content place a specially crafted ZIP file that contains a hidden script. The script is saved where anyone on the internet can trigger it, allowing the attacker to take control of the server. Update BookStack to the latest version and limit import permissions to trusted users to protect against this risk.
What to do
- Update bookstackapp bookstack to version 26.05.4 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| bookstackapp | bookstack | < 26.05.4 |
Original advisory text
BookStack before 26.05.4 Remote Code Execution via Book Cover
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename in the ZIP archive, which is stored in the public web root and executed by unauthenticated requests.
References
- https://github.com/BookStackApp/BookStack/commit/e210cc32e4cbb1efeae5c5c9d0fef8e... patch
- https://github.com/BookStackApp/BookStack product
- https://www.vulncheck.com/advisories/bookstack-before-26.05.4-remote-code-execut... third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-82450 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82450... Vendor Advisory
Severity
8.7
High
CVSS 3.1: 8.8 (MITRE)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Monitor software like this
Free during beta