CVE-2026-82450 HIGH

CVE-2026-82450: BookStack before 26.05.4 Remote Code Execution via Book Cover

Vendor Bookstackapp
Product bookstack
Weakness CWE-434 · Unrestricted file upload
Published August 29, 2026
Last update August 29, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename in the ZIP archive, which is stored in the public web root and executed by unauthenticated requests.

Key dates

02Disclosure timeline

August 29, 2026 CVE published

Related vulnerabilities

04Related CVE