Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-89022: BookStack lets attackers log in as any user
CVE-2026-89022 · published 24 days ago
Summary
BookStack's social login feature can be fooled into signing in a person without checking their password. An attacker can use one social account to gain access to another user's account, giving them full control of that user's data. Upgrade BookStack to version 26.05.5 or later, or turn off social login until you can apply the update.
What to do
- Update bookstackapp bookstack to version 26.05.5 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| bookstackapp | bookstack | < 26.05.5 |
Original advisory text
BookStack < 26.05.5 Authentication Bypass via Social Login Provider Confusion
BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers can authenticate at one enabled social provider using a user ID that matches an account linked to a different social provider, bypassing credential verification entirely because the SocialAuthService::handleLoginCallback query ignores the driver column when retrieving linked account records.
References
- https://www.bookstackapp.com/blog/bookstack-release-v26-05-5/
- https://www.vulncheck.com/advisories/bookstack-authentication-bypass-via-social-...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89022... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-89022 Vendor Advisory
- https://github.com/bookstackapp/bookstack Product
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-290Authentication Bypass by Spoofing
Timeline
Published15 Sep 2026
Updated9 Oct 2026
First seen15 Sep 2026
Track software like this
Free during beta