CVE-2026-93960

CVE & Vulnerabilities · September 22, 2026

CVE & Vulnerabilities·nvd.nist.gov

A newly disclosed vulnerability in Pixelfed, the decentralized photo-sharing platform, lets remote attackers bypass authentication through its OAuth scope handling and pull instance-peer data without valid credentials. The bug affects installations up through version 0.12.11, and a public exploit for it is already circulating. Site administrators are advised to update to a patched release as soon as possible.

// source: nvd.nist.gov ↗

Back to Blog