Improper access control in Zulip Server - #VU141414

 

Improper access control in Zulip Server - #VU141414

Published: August 11, 2026


Vulnerability identifier: #VU141414
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the event queue handling for public channel messages when registering an event queue with appropriate parameters or using an existing event queue after channel access was removed. A remote user can receive events for new messages in non-subscribed public channels to disclose sensitive information.


Affected software

Zulip Server

Remediation

Install security update from vendor's website.

Zulip Server - update to 12.2

External References

Related Security Bulletins