Improper access control in Synapse - #VU139991

 

Improper access control in Synapse - #VU139991

Published: July 29, 2026


Vulnerability identifier: #VU139991
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Synapse

Detailed vulnerability description

The vulnerability allows a remote user to disclose events from another room.

The vulnerability exists due to improper access control in the federation /get_missing_events endpoint when handling requests for missing events. A remote user can send a crafted request referencing events outside the specified room to disclose events from another room.

Exploitation requires the malicious homeserver to be joined to some room on the victim homeserver.


Remediation

Install security update from vendor's website.

Sources