CVE intelligence

CVE-2026-86112

BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers

Published 2026-09-05 · CVSS

medium

NIST record