User Permission Vulnerability in Venueless Chat Feature
CVE-2026-4982
What is CVE-2026-4982?
A vulnerability in the Venueless platform allows users with the 'update world' permission to potentially exfiltrate direct and channel messages from other worlds on the same server. This issue arises from a flaw in the chat reporting feature that inadvertently exposes messages between unauthorized users. Although the likelihood of an external attacker exploiting this vulnerability is low—due to the necessity of knowing the internal UUID of the chat channel—this poses a risk for users within the same server environment. Proper precautions and permissions management are essential to mitigate this flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Venueless 0.0.0 < 2026.3.27.e20083a
