CVE-2026-47777
mastodon
Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts consented to be featured in a remote Collection could lead to attackers bypassing the check and faking consent. An attacker could forge the FeatureAuthorization object that is used to verify consent to be featured in a Collection and thus make it appear as if an account is allowed to be in a Collection when it actually is not. While the FeatureAuthorization must reside on the same domain as the object it is for, a check is missing to make sure...
- CVSS
- 7.5
- EPSS
- 0.17% 6.39% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.16