Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2026-47777 — Detailed technical analysis of CVE-2026-47777, a high-severity authorization bypass in Mastodon's Featured Collections federation pipeline, including root cause, PoC, and patch. | Kitploit
Tools/GitHubGitHub/bekwiner/cve-2026-47777
Authentication & AuthorizationStatic AnalysisVulnerability AnalysisCode AnalysisWeb SecurityPenetration Testing
GitHubbekwiner/cve-2026-47777

cve-2026-47777

Detailed technical analysis of CVE-2026-47777, a high-severity authorization bypass in Mastodon's Featured Collections federation pipeline, including root cause, PoC, and patch.

View Repository
1232 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-47777 — Mastodon Featured Collections Authorization Bypass

Overview

I responsibly disclosed a High Severity Authorization Bypass vulnerability affecting Mastodon's experimental Featured Collections federation pipeline.

CVE ID: CVE-2026-47777

Affected Component

  • ActivityPub::VerifyFeaturedItemService

Weaknesses

  • CWE-345 — Insufficient Verification of Data Authenticity
  • CWE-863 — Incorrect Authorization

CVSS v3.1

ScoreVector
7.5 (High)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Vulnerability Summary

The Featured Collections verification pipeline accepted a forged FeatureAuthorization object without verifying that the authorization actually belonged to the featured account.

The verification logic only ensured that:

  • the authorization existed;
  • it originated from the expected domain;
  • it contained the expected ActivityPub fields.

However, it did not verify whether:

FeatureAuthorization.interactionTarget

matched the account being inserted into the Collection.

As a result, a malicious federated Mastodon instance could forge authorization documents and falsely indicate that arbitrary remote users had consented to appear in curated Featured Collections.

This resulted in an Authorization Bypass affecting federation integrity.


Root Cause

The vulnerability was caused by a missing identity binding inside:

ActivityPub::VerifyFeaturedItemService

The service failed to compare:

CollectionItem.object_uri

with

FeatureAuthorization.interactionTarget

Because this validation was missing, authorization objects could be reused for unrelated victim accounts.


Security Impact

An attacker could:

  • Forge FeatureAuthorization documents
  • Bypass user consent verification
  • Insert arbitrary remote accounts into Featured Collections
  • Create fake endorsements
  • Publish misleading curated collections
  • Impersonate user consent
  • Facilitate harassment and reputation abuse across federated instances

Impact: Federation Integrity (Integrity Only)

Confidentiality was not affected.


Technical Details

The missing validation was effectively:

return if @collection_item.object_uri != value_or_id(@authorization['interactionTarget'])

Without this identity check, authorization documents generated by an attacker-controlled domain could be accepted for unrelated users.


Research Methodology

The vulnerability was independently verified using multiple approaches:

  • Manual source code review
  • ActivityPub protocol analysis
  • Static code analysis
  • Ruby testing environment
  • Custom Python verification harness
  • Cross-comparison with existing Mastodon verification services

The custom Python verification harness tested every supported JSON-LD @context variation accepted by Mastodon's parser.

The analysis confirmed that the vulnerability originated from missing authorization binding, not JSON-LD parsing.


Proof of Concept (PoC)

The exploit workflow is:

  1. The attacker controls a federated Mastodon instance.
  2. A forged FeatureAuthorization object is published.
  3. The authorization references attacker-controlled resources.
  4. A victim account from another instance is inserted into the Collection.
  5. Mastodon accepts the forged authorization because object identity is never verified.

Result

A victim account appears as if it has consented to be featured, despite never granting authorization.


Fix

The issue was resolved by introducing an explicit identity validation between:

  • the featured object (CollectionItem.object_uri)
  • the authorization target (FeatureAuthorization.interactionTarget)

before accepting the authorization.


Timeline

DateEvent
2026Research completed
2026Responsible disclosure submitted
2026Vulnerability reproduced
2026CVE assigned (CVE-2026-47777)
2026Patch released (Mastodon 4.6.0-beta.1)

References

  • CVE: https://www.cve.org/CVERecord?id=CVE-2026-47777
  • GHSA: https://github.com/mastodon/mastodon/security/advisories/GHSA-vg36-gxjg-2v46
  • Patch: https://github.com/mastodon/mastodon/commit/22203f8aeb03e8f14dc62e253e83db39825a5bcf

Acknowledgements

Special thanks to the Mastodon Security Team for reviewing the report, validating the issue, assigning CVE-2026-47777, and implementing a coordinated security fix through responsible disclosure.


Author

Security Researcher: Bekzod

Responsible disclosure conducted in accordance with coordinated vulnerability disclosure practices.

Download Tool