Improper Authorization in Let's Chat Affects Room Archiving Functionality
CVE-2026-66751
Key Information:
- Vendor
Sdelements
- Status
- Vendor
- CVE Published:
- 28 July 2026
Badges
What is CVE-2026-66751?
The vulnerability present in Let's Chat versions 0.3.0 through 0.4.8 allows any authenticated user to archive any room on the server via an unrestricted DELETE request to the rooms handler, bypassing necessary ownership checks. This exploitation lets malicious users permanently remove access to private or password-protected rooms, posing a significant risk as there is no application-level mechanism for recovery. Restoring archived rooms would necessitate direct database intervention, escalating the risk for data loss and unauthorized actions.
Affected Version(s)
lets-chat 0.3.0 <= 0.4.8
lets-chat 0.3.0 <= 0.4.8
lets-chat 5b5f46f92696955c27864dbca8b33b5b6a39a502 <= 617207ff3c0c0bf8e3c7a915bd9ec03f1dd8390c
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
