THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86178 (MEDIUM 5.4) — Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URL

[NVD] CVE-2026-86178 (MEDIUM 5.4) — Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URL

mednvdPublished 2026-09-05

CVE-2026-86178 CVSS: 5.4 MEDIUM Published: 2026-09-05T11:16:46.537

Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URLs and author information without following the accou

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86178