Improper access control in Zulip Server - #VU151559
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose user IDs and email addresses of users they are not permitted to access.
The vulnerability exists due to improper access control in the direct-message typing notification endpoint when sending a typing notification to an inaccessible user. A remote user can send a typing notification addressed to an inaccessible user to disclose user IDs and email addresses.
The issue affects organizations configured to limit which users guests can see; email addresses are exposed only when the targeted user's email visibility setting permits guest access.