THREAT OPS › Threat News › [NVD] CVE-2026-86178 (MEDIUM 5.4) — Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URL
[NVD] CVE-2026-86178 (MEDIUM 5.4) — Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URL
CVE-2026-86178 CVSS: 5.4 MEDIUM Published: 2026-09-05T11:16:46.537
Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URLs and author information without following the accou
Indicators of compromise
- CVE-2026-86178cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86178