Improper access control in Zulip Server - #VU141414
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the event queue handling for public channel messages when registering an event queue with appropriate parameters or using an existing event queue after channel access was removed. A remote user can receive events for new messages in non-subscribed public channels to disclose sensitive information.