Incorrect authorization in Mastodon - #VU147213

 

Incorrect authorization in Mastodon - #VU147213

Published: September 7, 2026


Vulnerability identifier: #VU147213
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to restore their ability to log in.

The vulnerability exists due to incomplete permission checks in the admin API when handling requests from staff accounts disabled through the Freeze action. A remote privileged user can invoke admin API endpoints to restore their ability to log in.

The issue is specific to accounts disabled through the Freeze action; accounts demoted from their roles or suspended lose API access.


Affected software

Mastodon

Remediation

Install security update from vendor's website.

Mastodon - addressed in versions 4.4.24, 4.5.17, 4.6.7, 4.7.1

External References

Related Security Bulletins