CVE-2026-70617

🟡 Monitoruj

Brak weryfikacji uprawnień w Spacebar Server pozwala atakującym na dołączenie do prywatnych grup DM.

CVSS
8.1
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} handler to join private group DMs, read complete message history, post messages as a participant, and force-add third-party users without their consent.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-08-05 20:17:17 UTC
Ostatnia modyfikacja (NVD)2026-09-16 20:34:51 UTC
Referencje