Incorrect authorization in Mastodon - #VU147213
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to restore their ability to log in.
The vulnerability exists due to incomplete permission checks in the admin API when handling requests from staff accounts disabled through the Freeze action. A remote privileged user can invoke admin API endpoints to restore their ability to log in.
The issue is specific to accounts disabled through the Freeze action; accounts demoted from their roles or suspended lose API access.