Improper access control in Zulip Server - #VU151561
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in UserTopic row handling during channel moves when moving messages from a public channel to an inaccessible private channel. A remote user can move messages to a private channel to disclose private channel topic metadata.
The issue requires a non-subscriber to have a UserTopic row from muting or following the topic in the public channel.