Skip to main content
Vulnerability Database/CVE-2026-86178

CVE-2026-86178: Pixelfed Authentication Bypass Vulnerability

CVE-2026-86178 is an authentication bypass flaw in Pixelfed that allows attackers to access follower-only stories without proper authorization. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-86178 Overview

CVE-2026-86178 is a missing authorization vulnerability [CWE-862] in Pixelfed through version 0.12.9. The StoryComposeController react and comment endpoints fail to validate whether the requesting user follows the story author. Authenticated users can enumerate sequential story IDs and submit reactions or comments to retrieve media URLs and author metadata for follower-only stories.

The flaw affects the federated image-sharing platform's API routes and exposes private content intended only for approved followers. Exploitation requires only a valid authenticated account, no elevated privileges, and no user interaction from the victim.

Critical Impact

Authenticated attackers can bypass follower-only privacy controls to harvest private story media URLs and author information across a Pixelfed instance.

Affected Products

  • Pixelfed through version 0.12.9
  • StoryComposeController react endpoint
  • StoryComposeController comment endpoint

Discovery Timeline

  • 2026-09-05 - CVE-2026-86178 published to NVD
  • 2026-09-08 - Last updated in NVD database

Technical Details for CVE-2026-86178

Vulnerability Analysis

Pixelfed implements stories as follower-only ephemeral content. The API routes defined in routes/web-api.php at lines 154-155 accept a numeric story ID and dispatch to StoryComposeController react and comment handlers. Both handlers load the target story and perform the reaction or comment action without first checking whether the authenticated user follows the story author.

Because story IDs are sequential integers, an attacker can iterate the ID space and issue react or comment requests. The endpoint responses return media URLs and author information for stories the attacker would otherwise be unable to view. This exposes private content across every account on the instance that has active stories.

Root Cause

The root cause is missing authorization [CWE-862] in the react handler at app/Http/Controllers/StoryComposeController.php lines 487-501 and the comment handler at lines 566-580. Neither method invokes the follower-relationship check that the story viewing endpoints enforce. Authentication is verified, but the follow relationship between the requesting user and the story author is not evaluated before returning story data.

Attack Vector

Exploitation is performed over the network against the Pixelfed web API. An attacker registers or uses any authenticated account, then scripts sequential requests against the vulnerable react and comment routes with incrementing story ID values. Each successful response leaks the story media URL and author identity for stories belonging to accounts the attacker does not follow.

For technical details, see the VulnCheck Advisory on Pixelfed and the vulnerable code in the StoryComposeController source.

Detection Methods for CVE-2026-86178

Indicators of Compromise

  • Sequential enumeration of story IDs in requests to /api/v1.1/stories/*/react or /api/v1.1/stories/*/comment endpoints from a single authenticated session.
  • High volume of react or comment API calls from one account against stories belonging to accounts the user does not follow.
  • API responses containing story media URLs returned to users outside the story author's follower list.

Detection Strategies

  • Correlate application logs of react and comment endpoint requests against the follower graph to identify actions on stories where no follow relationship exists.
  • Implement rate-based alerting on the StoryComposeController react and comment routes to flag scripted enumeration behavior.
  • Review web server access logs for patterns of monotonically increasing story ID parameters from the same source IP or user token.

Monitoring Recommendations

  • Enable verbose logging on Pixelfed API endpoints handling story interactions and forward events to a centralized log store.
  • Baseline normal per-user rates for story reactions and comments, then alert on statistical outliers.
  • Monitor for accounts newly registered followed by immediate high-volume API activity against story endpoints.

How to Mitigate CVE-2026-86178

Immediate Actions Required

  • Upgrade Pixelfed to a release later than 0.12.9 once the maintainers publish a patched version incorporating the authorization check.
  • Restrict registration on public instances to reduce the pool of authenticated accounts able to enumerate story IDs.
  • Deploy web application firewall rules to rate-limit the react and comment story endpoints per authenticated user.

Patch Information

No fixed version is listed in the NVD entry at the time of publication. Monitor the Pixelfed GitHub repository for release notes addressing the missing follower validation in StoryComposeController. Review the GitHub OSS Documentation for the disclosure record.

Workarounds

  • Apply a local patch to StoryComposeController react and comment methods that invokes the same follower-relationship validation used by the story viewing endpoints.
  • Temporarily disable story reactions and comments at the reverse proxy by blocking requests to the affected API routes until a vendor fix is deployed.
  • Advise users with sensitive content to disable story posting until the instance is patched.
bash
# Example nginx snippet to block the vulnerable endpoints until patched
location ~* ^/api/v1\.1/stories/[0-9]+/(react|comment)$ {
    return 403;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.