CVE intelligence

CVE-2026-86178

Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated user

Published 2026-09-05 · CVSS

medium

NIST record