


Perceptive Security
SOC/SIEM Consultancy

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Creat…
Published:
29 August 2026 at 00:00:00
Alert date:
29 August 2026 at 17:02:49
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities
BookStack versions before 26.05.4 are affected by a remote code execution vulnerability in the portable ZIP import functionality. Authenticated users with Import Content and Create Books permissions can exploit this by uploading a PHP polyglot file disguised as a book cover image. The attack bypasses image extension validation by embedding a PHP file with a .php filename inside the ZIP archive. Once uploaded, the malicious file is stored in the public web root and can be executed by unauthenticated HTTP requests. This effectively allows privilege escalation from a limited authenticated user to full server-side code execution. The vulnerability has been patched in BookStack version 26.05.4. References include the official BookStack GitHub repository and a specific commit addressing the flaw.
Technical details
Mitigation steps:
Affected products:
BookStack before 26.05.4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82450
https://github.com/BookStackApp/BookStack
https://github.com/BookStackApp/BookStack/commit/e210cc32e4cbb1efeae5c5c9d0fef8e3c6a752e6
https://www.vulncheck.com/advisories/bookstack-before-26.05.4-remote-code-execution-via-book-cover
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
