BookStack Security Release v26.03.5
Dan Brown posted on the 21st of May 2026
BookStack v26.03.5 has been released.
This is a security release to address a brute-force based vulnerability related to multi-factor authentication, and to update project libraries to help avoid potential vulnerabilities that have been reported in those.
Upgrade is generally advised, but strongly so where multi-factor authentication is used & considered as a critical layer of defense.
Thanks to Stephen O. / Sakusen (Codeberg, Website) for responsibly reporting these issues.
Full List of Changes
- Updated PHP package versions.
- Updated MFA verification routes with rate limiting.
For More Information
You can find update instructions here.
If you have any questions or comments about this advisory:
- Ask in the BookStack Community.
- Open an issue in the BookStack Codeberg repository.
- Follow the BookStack security policy to contact someone privately.
Header Image Credits: Photo by Nabinregmi72 (cc-by-sa-4) - Image Modified