CVE-2026-5484
MEDIUMBookStackApp BookStack Chapter Export ExportFormatter.php chapterToMarkdown access control
Title source: cnaDescription
A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a manipulation of the argument pages can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 26.03.1 is able to address this issue. This patch is called 8a59895ba063040cc8dafd82e94024c406df3d04. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
References (8)
Core 8
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-355091 | BookStackApp BookStack Chapter Export ExportFormatter.php chapterToMarkdown access control
https://vuldb.com/vuln/355091
Signature, Permissions Required signature
permissions-required
VDB-355091 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/355091/cti
Third Party Advisory third-party-advisory
Submit #781762 | BookstackApp BookStack v25.12.9 Improper Access Controls
https://vuldb.com/submit/781762
Exploit exploit
https://github.com/Ghufran2/CVE-Bookstack/blob/main/Permission%20Bypass%20in%20Markdown%20Chapter%20Export
Related related
https://www.bookstackapp.com/blog/bookstack-release-v26-03-1/
Patch patch
https://github.com/BookStackApp/BookStack/commit/8a59895ba063040cc8dafd82e94024c406df3d04
Product product
https://github.com/BookStackApp/BookStack/
Scores
CVSS v3
5.3
EPSS
0.0032
EPSS Percentile
23.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-266
CWE-284
Status
published
Products (2)
BookStackApp/BookStack
26.03
BookStackApp/BookStack
26.03.1
Published
Apr 03, 2026
Tracked Since
Apr 04, 2026