Missing Authorization in Zulip Server - #VU151560
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in update_message event delivery when moving messages from a public channel to an inaccessible private channel. A remote user can move messages to a private channel to disclose the contents of future edits.
The issue requires a non-subscriber to retain a historical UserMessage row created in the public channel.