Medium severity5.4NVD Advisory· Published Sep 5, 2026
CVE-2026-86178
CVE-2026-86178
Description
Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URLs and author information without following the account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/geo-chen/oss/blob/main/Pixelfed.mdnvd
- github.com/pixelfed/pixelfed/blob/v0.12.9/app/Http/Controllers/StoryComposeController.phpnvd
- github.com/pixelfed/pixelfed/blob/v0.12.9/app/Http/Controllers/StoryComposeController.phpnvd
- github.com/pixelfed/pixelfed/blob/v0.12.9/routes/web-api.phpnvd
- www.vulncheck.com/advisories/pixelfed-through-0.12.9-unauthorized-story-access-via-apinvd
News mentions
0No linked articles in our index yet.