Improper access control in Zulip Server - #VU151557
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to impersonate other users by forging the sender of a group direct message.
The vulnerability exists due to improper access control in the mirroring API when handling API requests to send group direct messages. A remote user can forge a specific client identifier to impersonate another user in a group direct message.
Exploitation requires restricted account creation to a list of email domains and generally requires the impersonated user's email address to be visible to everyone. The forged conversation must include the user's own account.