Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers that fail to scope message queries to the requested channel. Authenticated users with MANAGE_MESSAGES permission in any controlled channel can delete arbitrary messages in other channels by routing delete requests through their own channel.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 20:17
Updated : 2026-09-17 18:17
NVD link : CVE-2026-69114
Mitre link : CVE-2026-69114
CVE.ORG link : CVE-2026-69114
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
