Improper access control in Zulip Server - #VU141410
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the GET /json/users endpoint when handling requests with include_custom_profile_fields for logged-out visitors. A remote attacker can send a specially crafted request to disclose sensitive information.
Only organizations using the public access option with web-public channels are vulnerable.