Improper access control in Synapse - #VU139996
Published: July 29, 2026
Synapse
Detailed vulnerability description
The vulnerability allows a remote user to change the destination of room aliases.
The vulnerability exists due to improper access control in room alias handling when participating in federated rooms. A remote user can cause a room alias to be redirected to a different room to change the destination of room aliases.
Homeservers that do not federate or only participate in a closed, trusted federation are not affected. Exploitation requires a malicious federated homeserver and either conspiring local authenticated users or a local user being tricked into joining a malicious federated room.