External risk intelligence

BookStack Social Login Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-89022

BookStack is a documentation and wiki platform commonly deployed as a public-facing web application. Since the vulnerability exists within its social login implementation—a feature typically exposed to the public internet for user authentication—the attack surface is commonly reachable in standard real-world deployments.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts BookStack, a documentation and wiki platform, by allowing unauthorized access through its social login feature. Attackers can bypass authentication by exploiting how the system handles different social login providers. The main concern is confirming if your BookStack instances are using this specific social login functionality and are therefore exposed.

  • Bypasses login by confusing social providers.
  • Leadership should understand its reach.
  • Confirm if social login is in use.

Attack Path

How an attacker could exploit the issue

An attacker could bypass authentication by exploiting how BookStack handles social logins. By using a specific user ID with one social login provider, an attacker could trick the system into logging them in as a different user linked to another social provider. This occurs because the system doesn't properly check which social provider is being used when linking accounts.

  • Attacker needs network access.
  • Triggered by logging in via social media.
  • Risk of unauthorized account access.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could bypass login and impersonate any user on a BookStack instance when social login is enabled and configured in a specific way. This could occur if an attacker uses a user ID associated with one social login provider to authenticate through a different provider that shares the same driver ID namespace, effectively tricking the system into granting access.

  • User accounts and access.
  • Attacker authenticates with a different provider.
  • Unauthorized access to user data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects BookStack's social login functionality, making it a concern for teams responsible for the application and its user authentication. The first step is to identify all BookStack instances, determine their exposure and business criticality, and locate the specific team or individual accountable for managing user authentication.

  • Application owners responsible for BookStack.
  • Verify social login reachability and criticality.
  • Plan remediation based on exposure and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is BookStack?

BookStack is a documentation and wiki platform designed for organizing and storing information. It is commonly used by teams to create collaborative knowledge bases. Users often configure it to support external authentication methods, such as social login, to simplify the process of accessing these document repositories.

How does CVE-2026-89022 cause an authentication bypass?

This vulnerability is an instance of Authentication Bypass by Spoofing (CWE-290). The application fails to verify the specific social login provider during the authentication callback. Because the system ignores which provider is being used to associate an account, an attacker can use credentials from one service to impersonate a user linked to a completely different social provider.

Does this flaw trigger if I do not use social login?

No. The vulnerability is specifically tied to the social login implementation. If your BookStack instance is configured to use only local email and password authentication, or if no external social providers are enabled, this specific mechanism is not active and cannot be triggered.

Is my BookStack instance at risk?

Halo Surface Signal indicates that because BookStack is frequently deployed as a public-facing web application, its social login feature is often exposed to the internet. If you have enabled social login, your instance is considered reachable to potential attackers who could attempt to exploit this logic error to bypass authentication.

What should I do to address this vulnerability?

Your first step is to confirm if your instance uses social login features. If it does, inventory your BookStack deployments to determine which are internet-facing and critical to your business operations. Consult the official vendor release notes for the required version update to resolve the identity verification logic.

References