Improper access control in Zulip Server - #VU141411
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote user to disclose profile information of other users.
The vulnerability exists due to improper access control in direct message draft saving when handling draft recipients. A remote user can save a direct message draft with recipients they are not allowed to access to disclose profile information of other users.
Only organizations that restrict guests\' ability to view other users using the relevant organization setting are vulnerable.