Data Exposure Vulnerability in Element Call Video Conferencing Application by Element
CVE-2026-48007

8.6HIGH

Key Information:

Vendor

Element-hq

Vendor
CVE Published:
7 August 2026

What is CVE-2026-48007?

Element Call, a native Matrix video conferencing application, has a vulnerability that inadvertently exposes private URLs in analytics data when configured to report to a PostHog server. Specifically, versions 0.5.17 through 0.19.3 improperly log sensitive information like the user's visited page URLs, which may include encryption passwords. This oversight puts users at risk, particularly those utilizing standalone instances such as https://call.element.io. While this vulnerability affects standalone configurations, it does not impact embedded applications because they utilize a different key distribution method. The issue has been addressed in version 0.19.4, and users are advised to explore available workarounds, including opting out of analytics or modifying the deployment configuration.

Affected Version(s)

element-call >= 0.5.17, < 0.19.4

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.