Data Exposure Vulnerability in Element Call Video Conferencing Application by Element
CVE-2026-48007
What is CVE-2026-48007?
Element Call, a native Matrix video conferencing application, has a vulnerability that inadvertently exposes private URLs in analytics data when configured to report to a PostHog server. Specifically, versions 0.5.17 through 0.19.3 improperly log sensitive information like the user's visited page URLs, which may include encryption passwords. This oversight puts users at risk, particularly those utilizing standalone instances such as https://call.element.io. While this vulnerability affects standalone configurations, it does not impact embedded applications because they utilize a different key distribution method. The issue has been addressed in version 0.19.4, and users are advised to explore available workarounds, including opting out of analytics or modifying the deployment configuration.
Affected Version(s)
element-call >= 0.5.17, < 0.19.4
