CVE-2026-86178 Overview
CVE-2026-86178 is a missing authorization vulnerability [CWE-862] in Pixelfed through version 0.12.9. The StoryComposeController react and comment endpoints fail to validate whether the requesting user follows the story author. Authenticated users can enumerate sequential story IDs and submit reactions or comments to retrieve media URLs and author metadata for follower-only stories.
The flaw affects the federated image-sharing platform's API routes and exposes private content intended only for approved followers. Exploitation requires only a valid authenticated account, no elevated privileges, and no user interaction from the victim.
Critical Impact
Authenticated attackers can bypass follower-only privacy controls to harvest private story media URLs and author information across a Pixelfed instance.
Affected Products
- Pixelfed through version 0.12.9
- StoryComposeController react endpoint
- StoryComposeController comment endpoint
Discovery Timeline
- 2026-09-05 - CVE-2026-86178 published to NVD
- 2026-09-08 - Last updated in NVD database
Technical Details for CVE-2026-86178
Vulnerability Analysis
Pixelfed implements stories as follower-only ephemeral content. The API routes defined in routes/web-api.php at lines 154-155 accept a numeric story ID and dispatch to StoryComposeController react and comment handlers. Both handlers load the target story and perform the reaction or comment action without first checking whether the authenticated user follows the story author.
Because story IDs are sequential integers, an attacker can iterate the ID space and issue react or comment requests. The endpoint responses return media URLs and author information for stories the attacker would otherwise be unable to view. This exposes private content across every account on the instance that has active stories.
Root Cause
The root cause is missing authorization [CWE-862] in the react handler at app/Http/Controllers/StoryComposeController.php lines 487-501 and the comment handler at lines 566-580. Neither method invokes the follower-relationship check that the story viewing endpoints enforce. Authentication is verified, but the follow relationship between the requesting user and the story author is not evaluated before returning story data.
Attack Vector
Exploitation is performed over the network against the Pixelfed web API. An attacker registers or uses any authenticated account, then scripts sequential requests against the vulnerable react and comment routes with incrementing story ID values. Each successful response leaks the story media URL and author identity for stories belonging to accounts the attacker does not follow.
For technical details, see the VulnCheck Advisory on Pixelfed and the vulnerable code in the StoryComposeController source.
Detection Methods for CVE-2026-86178
Indicators of Compromise
- Sequential enumeration of story IDs in requests to /api/v1.1/stories/*/react or /api/v1.1/stories/*/comment endpoints from a single authenticated session.
- High volume of react or comment API calls from one account against stories belonging to accounts the user does not follow.
- API responses containing story media URLs returned to users outside the story author's follower list.
Detection Strategies
- Correlate application logs of react and comment endpoint requests against the follower graph to identify actions on stories where no follow relationship exists.
- Implement rate-based alerting on the StoryComposeController react and comment routes to flag scripted enumeration behavior.
- Review web server access logs for patterns of monotonically increasing story ID parameters from the same source IP or user token.
Monitoring Recommendations
- Enable verbose logging on Pixelfed API endpoints handling story interactions and forward events to a centralized log store.
- Baseline normal per-user rates for story reactions and comments, then alert on statistical outliers.
- Monitor for accounts newly registered followed by immediate high-volume API activity against story endpoints.
How to Mitigate CVE-2026-86178
Immediate Actions Required
- Upgrade Pixelfed to a release later than 0.12.9 once the maintainers publish a patched version incorporating the authorization check.
- Restrict registration on public instances to reduce the pool of authenticated accounts able to enumerate story IDs.
- Deploy web application firewall rules to rate-limit the react and comment story endpoints per authenticated user.
Patch Information
No fixed version is listed in the NVD entry at the time of publication. Monitor the Pixelfed GitHub repository for release notes addressing the missing follower validation in StoryComposeController. Review the GitHub OSS Documentation for the disclosure record.
Workarounds
- Apply a local patch to StoryComposeController react and comment methods that invokes the same follower-relationship validation used by the story viewing endpoints.
- Temporarily disable story reactions and comments at the reverse proxy by blocking requests to the affected API routes until a vendor fix is deployed.
- Advise users with sensitive content to disable story posting until the instance is patched.
# Example nginx snippet to block the vulnerable endpoints until patched
location ~* ^/api/v1\.1/stories/[0-9]+/(react|comment)$ {
return 403;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
