
Detailed technical analysis of CVE-2026-47777, a high-severity authorization bypass in Mastodon's Featured Collections federation pipeline, including root cause, PoC, and patch.
I responsibly disclosed a High Severity Authorization Bypass vulnerability affecting Mastodon's experimental Featured Collections federation pipeline.
CVE ID: CVE-2026-47777
ActivityPub::VerifyFeaturedItemService| Score | Vector |
|---|---|
| 7.5 (High) | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
The Featured Collections verification pipeline accepted a forged FeatureAuthorization object without verifying that the authorization actually belonged to the featured account.
The verification logic only ensured that:
However, it did not verify whether:
FeatureAuthorization.interactionTarget
matched the account being inserted into the Collection.
As a result, a malicious federated Mastodon instance could forge authorization documents and falsely indicate that arbitrary remote users had consented to appear in curated Featured Collections.
This resulted in an Authorization Bypass affecting federation integrity.
The vulnerability was caused by a missing identity binding inside:
ActivityPub::VerifyFeaturedItemService
The service failed to compare:
CollectionItem.object_uri
with
FeatureAuthorization.interactionTarget
Because this validation was missing, authorization objects could be reused for unrelated victim accounts.
An attacker could:
FeatureAuthorization documentsImpact: Federation Integrity (Integrity Only)
Confidentiality was not affected.
The missing validation was effectively:
return if @collection_item.object_uri != value_or_id(@authorization['interactionTarget'])
Without this identity check, authorization documents generated by an attacker-controlled domain could be accepted for unrelated users.
The vulnerability was independently verified using multiple approaches:
The custom Python verification harness tested every supported JSON-LD @context variation accepted by Mastodon's parser.
The analysis confirmed that the vulnerability originated from missing authorization binding, not JSON-LD parsing.
The exploit workflow is:
FeatureAuthorization object is published.A victim account appears as if it has consented to be featured, despite never granting authorization.
The issue was resolved by introducing an explicit identity validation between:
CollectionItem.object_uri)FeatureAuthorization.interactionTarget)before accepting the authorization.
| Date | Event |
|---|---|
| 2026 | Research completed |
| 2026 | Responsible disclosure submitted |
| 2026 | Vulnerability reproduced |
| 2026 | CVE assigned (CVE-2026-47777) |
| 2026 | Patch released (Mastodon 4.6.0-beta.1) |
Special thanks to the Mastodon Security Team for reviewing the report, validating the issue, assigning CVE-2026-47777, and implementing a coordinated security fix through responsible disclosure.
Security Researcher: Bekzod
Responsible disclosure conducted in accordance with coordinated vulnerability disclosure practices.