# BookStack v26.03.2 — BookStack v26.03.2 - Product: BookStack (https://whatsnew.fyi/product/bookstack) - Vendor: Dan Brown - Date: 2026-03-23 - Version: v26.03.2 - Original notes: https://github.com/BookStackApp/BookStack/releases/tag/v26.03.2 - Permalink: https://whatsnew.fyi/product/bookstack/releases/v26.03.2 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Fixed vulnerability where the registration form could be manipulated to gain access to additional roles - **fixed** — Updated user creation to only use validated input from registration - **changed** — Updated PHP package versions - **changed** — Updated translations with latest Crowdin changes - **changed** — Updated WYSIWYG editors to have consistent collapsible block double click behavior ###### Security Release * [Update Instructions](https://www.bookstackapp.com/docs/admin/updates) * [Update details on blog](https://www.bookstackapp.com/blog/bookstack-release-v26-03-2/) This is a security release to address a vulnerability where the registration form could be manipulated to gain access to additional roles. Upgrade is **very strongly** advised if your instance has user registration enabled. Thanks to Kwonyong Lee ([LinkedIn](https://www.linkedin.com/in/kwonyong-lee-854bb0372)) for responsibly reporting this issue. Also thanks to Boustani OSAMA ([LinkedIn](https://www.linkedin.com/in/boustani-osama-cy/)) for also reporting this before public announcement. ###### Full List of Changes * Updated user creation to only use validated input from registration. * Updated PHP package versions. * Updated translations with latest Crowdin changes. ([#6064](https://github.com/BookStackApp/BookStack/pull/6064)) * Updated PHP_CodeSniffer repository link. Thanks to [@rodrigoprimo](https://github.com/BookStackApp/BookStack/pull/6060). ([#6060](https://github.com/BookStackApp/BookStack/pull/6060)) * Updated WYSIWYG editors to have consistent collapsible block double click behavior. ([#6059](https://github.com/BookStackApp/BookStack/issues/6059))