CVE-2026-67204

BookStack < 26.05.4 Broken Access Control via Image Gallery API

BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints. Attackers can supply a user avatar's ID to the API controller, which loads any image type without the web controller's gallery and drawio restrictions, and when the avatar's uploaded_to field matches a page ID accessible to the attacker, the authorization check passes allowing the attacker to rename, replace, or delete the target user's avatar without requiring user-management permission.


We have discovered 368 live websites that are affected by CVE-2026-67204.

Run a Free Instant Scan




Affected Software

Product  BookStack
Category Documentation Tools
Vulnerable Domains368 live websites (100% of BookStack install base)
Vulnerable Versions
  • from 0 through 26.5.4
Vulnerable Versions Count72 versions ( 100% of all versions)



Details

  • Published - Aug 24, 2026
  • Updated - Aug 24, 2026

Credits

  • ByteMe.Red (finder)
  • VulnCheck (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-67204
United States95 websites



Germany89 websites
France36 websites
Russia18 websites
Canada12 websites
Spain11 websites
Brazil10 websites
Switzerland9 websites
Singapore9 websites
Czech Republic8 websites

Website Distribution by TLD

Number of websites using CVE-2026-67204
.com98 websites
.org45 websites
.de38 websites
.net21 websites
.fr14 websites
.ru12 websites
.eu7 websites
.ca7 websites
.edu6 websites
.com.br6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-67204

Top websites that are affected by CVE-2026-67204. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.**************.net Germany**,***
****.********.me United States**,***
************.****.**.***.br Brazil**,***
*******.org Singapore***,***
****.**************.de Germany***,***
****.***********.com France***,***
****.**************.es Spain***,***
*******.***********.ru Russia***,***
****.**************.se Sweden***,***
****.********.ru Russia*,***,***
See full domain list

FAQ

A total of 368 websites have been identified as vulnerable to CVE-2026-67204, based on global website indexing conducted by WebTechSurvey.
The BookStack is affected by the CVE-2026-67204 vulnerability.
BookStack versions up to 26.5.4 are vulnerable to CVE-2026-67204.
CVE-2026-67204 is resolved in version 26.5.4 of BookStack.