CyberRota Analysis
AI-GeneratedThe vulnerability allows unauthenticated attackers to bypass authentication in BookStack by exploiting the social login feature, enabling them to log in as any user linked to a different social provider. This can lead to unauthorized access to sensitive user data and functionalities within the application. Organizations using affected versions of BookStack should prioritize patching this vulnerability to protect user accounts and maintain system integrity.
Original NVD Description
BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers can authenticate at one enabled social provider using a user ID that matches an account linked to a different social provider, bypassing credential verification entirely because the SocialAuthService::handleLoginCallback query ignores the driver column when retrieving linked account records.