Improper access control in Synapse - #VU139991
Published: July 29, 2026
Synapse
Detailed vulnerability description
The vulnerability allows a remote user to disclose events from another room.
The vulnerability exists due to improper access control in the federation /get_missing_events endpoint when handling requests for missing events. A remote user can send a crafted request referencing events outside the specified room to disclose events from another room.
Exploitation requires the malicious homeserver to be joined to some room on the victim homeserver.