CVE-2026-86285 | BookStack up to 26.05.2 Attachment Edit Endpoint AttachmentController.php getUpdateForm ID access control
A vulnerability labeled as problematic has been found in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. The manipulation of the argument ID results in improper access controls.
This vulnerability is cataloged as CVE-2026-86285. The attack may be launched remotely. Furthermore, there is an exploit available.
It is advisable to implement a patch to correct this issue.