Impact
BookStack before version 26.05.4 has a broken access control flaw that allows authenticated users who have image-update or image-delete permissions to change or delete the avatars of other users. By providing an avatar’s identifier to the Image Gallery API, the request bypasses the web controller’s gallery and drawio restrictions because the API does not enforce content‑type checks. If the avatar’s uploaded_to page is one the attacker can access, the authorization system incorrectly authorizes the action, letting the attacker rename, replace, or remove the target avatar without needing user‑management rights.
Affected Systems
BookStack applications running any release earlier than 26.05.4 on the BookStackApp platform are vulnerable. Users of these affected builds should consider their deployed instance version; the issue does not affect releases 26.05.4 and newer.
Risk and Exploitability
This flaw has a medium CVSS score of 5.3 and is currently not listed in the CISA KEV catalog. The EPSS score is unavailable, but the vulnerability requires an authenticated API user with image‑update or image‑delete permissions who can also read the target page. Once those prerequisites are met, an attacker can abuse the API to alter or remove another user’s avatar, potentially enabling social‑engineering attacks or disrupting user identification.
OpenCVE Enrichment