Improper access control in Synapse - #VU139994
Published: July 29, 2026
Synapse
Detailed vulnerability description
The vulnerability allows a remote user to disclose authorization events from another room.
The vulnerability exists due to improper access control in the federation /event_auth endpoint when handling requests for event authorization data by event ID. A remote user can send a specially crafted federation request to disclose authorization events from another room.
Exploitation requires the malicious homeserver to be joined to some room on the victim homeserver.