User Permission Vulnerability in Venueless Chat Feature
CVE-2026-4982

7.3HIGH

Key Information:

Vendor

Pretix

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-4982?

A vulnerability in the Venueless platform allows users with the 'update world' permission to potentially exfiltrate direct and channel messages from other worlds on the same server. This issue arises from a flaw in the chat reporting feature that inadvertently exposes messages between unauthorized users. Although the likelihood of an external attacker exploiting this vulnerability is low—due to the necessity of knowing the internal UUID of the chat channel—this poses a risk for users within the same server environment. Proper precautions and permissions management are essential to mitigate this flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Venueless 0.0.0 < 2026.3.27.e20083a

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pratik Karan
.