CVE-2026-89022 | bookstackapp BookStack up to 26.05.4 Social Login handleLoginCallback driver improper authentication
A vulnerability labeled as critical has been found in bookstackapp BookStack up to 26.05.4. This impacts the function SocialAuthService::handleLoginCallback of the component Social Login. The manipulation of the argument driver results in improper authentication.
This vulnerability was named CVE-2026-89022. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More