CVE-2026-86178
EUVD-2026-7197705.09.2026, 11:16
Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URLs and author information without following the account.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| pixelfed | pixelfed | 𝑥 ≤ 0.12.9 | CNA |
Common Weakness Enumeration
References