CVE-2026-61463 – Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account

​CVE ID :CVE-2026-61463

Published : July 13, 2026, 6:16 p.m. | 38 minutes ago

Description :Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted PATCH request with owner: true, then re-authenticate to obtain an admin JWT token granting full system access.

Severity: 8.8 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More