CVE-2026-27468 | Mastodon up to 4.4.13/4.5.6 FASP Feature EXPERIMENTAL_FEATURES authorization (GHSA-qgmm-vr4c-ggjg)
A vulnerability classified as problematic was found in Mastodon up to 4.4.13/4.5.6. Affected by this issue is some unknown functionality of the component FASP Feature. The manipulation of the argument EXPERIMENTAL_FEATURES results in missing authorization.
This vulnerability is cataloged as CVE-2026-27468. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.