Improper access control in Zulip Server - #VU151557

 

Improper access control in Zulip Server - #VU151557

Published: September 22, 2026


Vulnerability identifier: #VU151557
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to impersonate other users by forging the sender of a group direct message.

The vulnerability exists due to improper access control in the mirroring API when handling API requests to send group direct messages. A remote user can forge a specific client identifier to impersonate another user in a group direct message.

Exploitation requires restricted account creation to a list of email domains and generally requires the impersonated user's email address to be visible to everyone. The forged conversation must include the user's own account.


Affected software

Zulip Server

Remediation

Install security update from vendor's website.

Zulip Server - update to 12.3

External References

Related Security Bulletins