CVE-2026-86178
Dashboard / Vulnerabilities / CVE-2026-86178
CVE-2026-86178
Summary: Pixelfed through 0.12.9 Unauthorized Story Access via API
Details: Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URLs and author information without following the account.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86178.json, https://nvd.nist.gov/vuln/detail/CVE-2026-86178, https://www.vulncheck.com/advisories/pixelfed-through-0.12.9-unauthorized-story-access-via-api, https://github.com/pixelfed/pixelfed, https://github.com/pixelfed/pixelfed/blob/v0.12.9/app/Http/Controllers/StoryComposeController.php#L487-L501, https://github.com/pixelfed/pixelfed/blob/v0.12.9/app/Http/Controllers/StoryComposeController.php#L566-L580, https://github.com/pixelfed/pixelfed/blob/v0.12.9/routes/web-api.php#L154-L155, https://github.com/geo-chen/oss/blob/main/Pixelfed.md
Affected packages
Package
Name:
Purl:
