Improper access control in Synapse - CVE-2023-43796
Published: October 31, 2023 / Updated: May 4, 2026
Synapse
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in cached remote user device information handling when querying device information. A remote attacker can query cached device information of remote users to disclose sensitive information.
This can be used to enumerate remote users known to the homeserver.