Improper access control in Synapse - #VU139994

 

Improper access control in Synapse - #VU139994

Published: July 29, 2026


Vulnerability identifier: #VU139994
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Synapse

Detailed vulnerability description

The vulnerability allows a remote user to disclose authorization events from another room.

The vulnerability exists due to improper access control in the federation /event_auth endpoint when handling requests for event authorization data by event ID. A remote user can send a specially crafted federation request to disclose authorization events from another room.

Exploitation requires the malicious homeserver to be joined to some room on the victim homeserver.


Remediation

Install security update from vendor's website.

Sources