SB2026092223 - Multiple vulnerabilities in Zulip Server



SB2026092223 - Multiple vulnerabilities in Zulip Server

Published: September 22, 2026

Security Bulletin ID SB2026092223
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 20% Low 80%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to impersonate other users by forging the sender of a group direct message.

The vulnerability exists due to improper access control in the mirroring API when handling API requests to send group direct messages. A remote user can forge a specific client identifier to impersonate another user in a group direct message.

Exploitation requires restricted account creation to a list of email domains and generally requires the impersonated user's email address to be visible to everyone. The forged conversation must include the user's own account.


2) Improper Output Neutralization for Logs (CVE-ID: N/A)

CWE-ID: CWE-117 - Improper Output Neutralization for Logs

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to forge or obscure log entries.

The vulnerability exists due to improper output neutralization for logs in the /report/csp_violations endpoint when processing crafted CSP violation reports. A remote attacker can submit a crafted report containing control characters to forge or obscure log entries.

The endpoint is unauthenticated.


3) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose user IDs and email addresses of users they are not permitted to access.

The vulnerability exists due to improper access control in the direct-message typing notification endpoint when sending a typing notification to an inaccessible user. A remote user can send a typing notification addressed to an inaccessible user to disclose user IDs and email addresses.

The issue affects organizations configured to limit which users guests can see; email addresses are exposed only when the targeted user's email visibility setting permits guest access.


4) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in update_message event delivery when moving messages from a public channel to an inaccessible private channel. A remote user can move messages to a private channel to disclose the contents of future edits.

The issue requires a non-subscriber to retain a historical UserMessage row created in the public channel.


5) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in UserTopic row handling during channel moves when moving messages from a public channel to an inaccessible private channel. A remote user can move messages to a private channel to disclose private channel topic metadata.

The issue requires a non-subscriber to have a UserTopic row from muting or following the topic in the public channel.


Remediation

Install update from vendor's website.