Skip to main content
Vulnerability Database/CVE-2026-93960

CVE-2026-93960: Pixelfed OAuth Authentication Bypass Vulnerability

CVE-2026-93960 is an authentication bypass flaw in Pixelfed affecting versions up to 0.12.11, allowing remote attackers to circumvent OAuth authentication controls. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-93960 Overview

CVE-2026-93960 is a missing authentication vulnerability [CWE-287] in Pixelfed, an open-source federated image-sharing platform. The flaw affects versions up to and including 0.12.11 and resides in the instancePeers function of app/Http/Controllers/Api/ApiV1Controller.php within the OAuth Scope Handler component. Manipulation of the id argument triggers an authentication check bypass on API endpoints intended to be gated by OAuth scopes. The issue is exploitable remotely by an attacker holding a low-privilege API token. The maintainers addressed the flaw in Pixelfed release v0.12.10 with commit 68dca5097305fa0065d029587b2233524636025a.

Critical Impact

A remote authenticated user can invoke OAuth scope-restricted API actions on the Pixelfed instance without possessing the required token capability, allowing unauthorized modifications to social graph state such as follower relationships.

Affected Products

  • Pixelfed versions up to 0.12.11 (patched in v0.12.10 release branch per vendor advisory)
  • Component: OAuth Scope Handler in app/Http/Controllers/Api/ApiV1Controller.php
  • Function: instancePeers and related token-scoped account endpoints

Discovery Timeline

  • 2026-09-20 - CVE-2026-93960 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-93960

Vulnerability Analysis

Pixelfed exposes a Mastodon-compatible API where actions such as following, unfollowing, and querying instance peers are gated by OAuth token scopes. The vulnerability originates from insufficient validation in scope-checked handlers within ApiV1Controller.php. The controller called tokenCan('follow') on the authenticated user without first verifying that the request carried an actual OAuth access token. Requests authenticated through alternative session mechanisms therefore satisfied the abort_if user check but never had their token scopes evaluated, effectively bypassing the OAuth scope enforcement layer.

Root Cause

The root cause is a missing precondition check on $request->user()->token(). When no token object exists on the authenticated user, calling tokenCan() returns a value that does not correctly deny access, so scope-restricted endpoints proceed to execute. The patch adds an explicit assertion that both a user and a valid token must be present before scope evaluation occurs.

Attack Vector

A remote attacker with low-privilege access to the Pixelfed API can craft requests to scope-restricted endpoints such as accountRemoveFollowById and reach protected functionality without holding the corresponding OAuth scope. The attack is network-based, requires low privileges, and needs no user interaction. Impact is limited to integrity of specific API-controlled state; confidentiality and availability are not directly affected.

php
// Patch: app/Http/Controllers/Api/ApiV1Controller.php
public function accountRemoveFollowById(Request $request, $id)
{
-    abort_if(! $request->user(), 403);
+    abort_if(! $request->user() || ! $request->user()->token(), 403);
     abort_unless($request->user()->tokenCan('follow'), 403);

     $pid = $request->user()->profile_id;

Source: GitHub commit 68dca50. The fix ensures the request carries a real OAuth token before scope enforcement runs, closing the bypass path.

Detection Methods for CVE-2026-93960

Indicators of Compromise

  • Unexpected follow or unfollow API calls from user sessions whose OAuth tokens do not include the follow scope.
  • HTTP requests to /api/v1/accounts/{id}/unfollow or related scope-gated endpoints returning 200 when the caller's registered token scopes should have caused a 403.
  • Sudden changes in follower or peer relationships that do not correlate with legitimate client applications.

Detection Strategies

  • Enable verbose Laravel request logging on ApiV1Controller routes and correlate the caller's token scopes against the endpoint invoked.
  • Compare OAuth access_tokens scope values in the Pixelfed database against the API actions performed by each token identifier.
  • Alert on API traffic that authenticates via web session cookies rather than Authorization: Bearer headers when hitting endpoints reserved for scoped tokens.

Monitoring Recommendations

  • Ship Pixelfed application and web server logs to a centralized log store and retain them long enough to reconstruct pre-patch activity.
  • Baseline the ratio of scoped API calls per token and alert on outliers indicating scope bypass attempts.
  • Monitor the Pixelfed GitHub repository for follow-on advisories referencing commit 68dca50 or the OAuth scope handler.

How to Mitigate CVE-2026-93960

Immediate Actions Required

  • Upgrade Pixelfed to the patched release documented in GitHub Release v0.12.10, which incorporates commit 68dca5097305fa0065d029587b2233524636025a.
  • Audit issued OAuth tokens and revoke any tokens created by unrecognized client applications during the exposure window.
  • Review recent follow, unfollow, and peer-management actions to identify unauthorized state changes and reverse them where appropriate.

Patch Information

The fix is delivered in Pixelfed release v0.12.10 via commit 68dca5097305fa0065d029587b2233524636025a, merged through Pull Request #6774. The change adds a missing token presence check to scope-gated controller actions in app/Http/Controllers/Api/ApiV1Controller.php. Additional context is available in GitHub Issue #6643 and the VulDB entry for CVE-2026-93960.

Workarounds

  • If immediate upgrade is not possible, backport the two-line change from commit 68dca50 to add || ! $request->user()->token() to the abort_if guard on affected controller methods.
  • Restrict access to the Pixelfed API at the reverse proxy layer so that scope-restricted routes require an Authorization: Bearer header and reject cookie-only sessions.
  • Rotate OAuth client secrets and force reissuance of user access tokens after applying the patch.
bash
# Upgrade Pixelfed to the patched release
cd /path/to/pixelfed
git fetch --all --tags
git checkout v0.12.10
composer install --no-dev --optimize-autoloader
php artisan migrate --force
php artisan config:cache
php artisan route:cache

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.