Improper access control in Zulip Server - #VU141411

 

Improper access control in Zulip Server - #VU141411

Published: August 11, 2026


Vulnerability identifier: #VU141411
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose profile information of other users.

The vulnerability exists due to improper access control in direct message draft saving when handling draft recipients. A remote user can save a direct message draft with recipients they are not allowed to access to disclose profile information of other users.

Only organizations that restrict guests\' ability to view other users using the relevant organization setting are vulnerable.


Affected software

Zulip Server

Remediation

Install security update from vendor's website.

Zulip Server - update to 12.2

External References

Related Security Bulletins