CyberRota Analysis
AI-GeneratedAuthenticated API users with image-update or image-delete permissions in BookStack versions prior to 26.05.4 can exploit a broken access control vulnerability to manipulate other users' avatars. By bypassing content-type restrictions in the Image Gallery API, attackers can rename, replace, or delete avatars if they have access to the corresponding page ID. Organizations using affected versions should prioritize patching to mitigate potential unauthorized avatar manipulation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints. Attackers can supply a user avatar's ID to the API controller, which loads any image type without the web controller's gallery and drawio restrictions, and when the avatar's uploaded_to field matches a page ID accessible to the attacker, the authorization check passes allowing the attacker to rename, replace, or delete the target user's avatar without requiring user-management permission.