Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-89022: BookStack lets attackers log in as any user

CVE-2026-89022 · published 24 days ago
Summary

BookStack's social login feature can be fooled into signing in a person without checking their password. An attacker can use one social account to gain access to another user's account, giving them full control of that user's data. Upgrade BookStack to version 26.05.5 or later, or turn off social login until you can apply the update.

What to do
  • Update bookstackapp bookstack to version 26.05.5 or later.
Affected software
VendorProductAffected versions
bookstackapp bookstack < 26.05.5
Original advisory text
BookStack < 26.05.5 Authentication Bypass via Social Login Provider Confusion
BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers can authenticate at one enabled social provider using a user ID that matches an account linked to a different social provider, bypassing credential verification entirely because the SocialAuthService::handleLoginCallback query ignores the driver column when retrieving linked account records.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-290Authentication Bypass by Spoofing
Timeline
Published15 Sep 2026
Updated9 Oct 2026
First seen15 Sep 2026
Sources
CVE-2026-89022 · MITRE
Track software like this
Free during beta