# bookstack security

Published articles for bookstack security.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## BookStack Security Update Patches Critical RCE Flaw in v26.05.4

DevFeed: [BookStack Security Update Patches Critical RCE Flaw in v26.05.4](<https://devfeed.tech/articles/bookstack-security-update-patches-critical-rce-flaw-in-v26-05-4-10718.md>)

Original publisher: [Read original article](<https://selfhostlab.io/bookstack-security-update-26-05-4/>)

Author: Christian Rakoot

Published: 2026-08-31T06:36:25Z

Content type: news

Language: en

Sources: [Self Host Lab](<https://devfeed.tech/sources/self-host-lab.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [bookstack-security](<https://devfeed.tech/tags/bookstack-security.md>), [news](<https://devfeed.tech/tags/news.md>), [news-personal-cloud](<https://devfeed.tech/tags/news-personal-cloud.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [personal-cloud](<https://devfeed.tech/tags/personal-cloud.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

BookStack v26.05.4 is a dedicated security release that fixes four vulnerabilities, including a critical authenticated remote code execution flaw involving crafted ZIP imports, an XSS issue, and two draft-page permission bypasses. The article recommends updating and restricting import permissions if an immediate update is not possible.

### Source excerpt

BookStack v26.05.4, released August 24, 2026, is a dedicated security update patching four vulnerabilities: a critical RCE (CVE-2026-82450) exploitable through crafted ZIP imports, an XSS flaw in drawing endpoints, and two permission bypasses affecting draft pages. The BookStack team recommends updating everyone, but especially instances where untrusted users hold general or edit-level access to content.