Matrix Server Key Generation Vulnerability in Element Server Suite Community Edition
CVE-2026-24044

9.2CRITICAL

Key Information:

Vendor

Element-hq

Vendor
CVE Published:
12 February 2026

What is CVE-2026-24044?

The Element Server Suite Community Edition contains a vulnerability in its Helm Chart that utilizes an insecure method for generating Matrix server keys. If certain configuration settings are not properly disabled, attackers could potentially regenerate the same key pair, gaining the ability to impersonate the victim server. This poses risks to the confidentiality, integrity, and availability of communication within Matrix rooms involving the compromised server. Although prior conversations in end-to-end encrypted rooms remain secure, this vulnerability emphasizes the need for secure key generation practices. Users are advised to update to matrix-tools version 0.5.7 or later, included with ESS Community Helm Chart 25.12.1, to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ess-helm < 25.12.1

matrix-tools < 0.5.7

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.