PT-2026-30222 · Bookstackapp+1 · Bookstack

·

CVE-2026-5484

·

Published

2026-04-03

·

Updated

2026-07-20

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions BookStack versions prior to 26.03.1
Description An issue exists in the Chapter Export Handler component within the chapterToMarkdown() function of the app/Exports/ExportFormatter.php file. A remote attacker can manipulate the pages argument to bypass access controls.
Recommendations Upgrade to version 26.03.1.

Exploit

Fix

Improper Access Control

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5484

Affected Products

Bookstack