Improper access control in Mastodon - CVE-2026-47777
Published: May 23, 2026
Mastodon
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass consent checks and falsify authorization for inclusion in a remote collection.
The vulnerability exists due to improper access control in the remote Collections consent verification logic when processing a forged FeatureAuthorization object. A remote attacker can forge a FeatureAuthorization object to bypass consent checks and falsify authorization for inclusion in a remote collection.
Only instances with the experimental "Collections" feature enabled are vulnerable.