CVE-2026-23961

Mastodon may allow a remote suspension bypass

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent interactions. However, some logic errors allow already-known posts from such suspended users to appear in timelines if boosted. Furthermore, under certain circumstances, previously-unknown posts from suspended users can be processed. This issue allows old posts from suspended users to occasionally end up on timelines on all Mastodon versions. Additionally, on Mastodon versions from v4.5.0 to v4.5.4, v4.4.5 to v4.4.11, v4.3.13 to v4.3.17, and v4.2.26 to v4.2.29, remote suspended users can partially bypass the suspension to get new posts in. Mastodon versions v4.5.5, v4.4.12, v4.3.18 are patched.


We have discovered 1,372 live websites that are affected by CVE-2026-23961.

Run a Free Instant Scan




Affected Software

Product  Mastodon
Category Message Boards
Vulnerable Domains1,372 live websites (100% of Mastodon install base)
Vulnerable Versions
  • from 0 through 4.3.18
  • from 4.4 through 4.4.12
  • from 4.5 through 4.5.5
Vulnerable Versions Count68 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Jan 22, 2026
  • Updated - Jan 22, 2026

Website Distribution by Country

Number of websites using CVE-2026-23961
United States341 websites



France429 websites
Germany271 websites
Japan93 websites
Singapore43 websites
GB25 websites
Canada21 websites
Netherlands16 websites
Austria15 websites

Website Distribution by TLD

Number of websites using CVE-2026-23961
.com160 websites
.net107 websites
.org87 websites
.de41 websites
.jp30 websites
.fr27 websites
.eu26 websites
.info23 websites
.io22 websites
.nl14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-23961

Top websites that are affected by CVE-2026-23961. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.net Germany***
*********.org United States**,***
*****.social Germany**,***
********.**********.ca Canada**,***
*********.com United States**,***
********.art France**,***
********.xyz Germany**,***
*****.fr France**,***
*****.social Germany**,***
********.***.org United States***,***
See full domain list

FAQ

CVE-2026-23961 is Incorrect Authorization in Mastodon
A total of 1,372 websites have been identified as vulnerable to CVE-2026-23961, based on global website indexing conducted by WebTechSurvey.
The Mastodon is affected by the CVE-2026-23961 vulnerability.
Mastodon versions up to 4.5.5 are vulnerable to CVE-2026-23961.
CVE-2026-23961 is resolved in version 4.5.5 of Mastodon.