Improper Authorization in Let's Chat Affects Room Archiving Functionality
CVE-2026-66751

5.3MEDIUM

Key Information:

Vendor

Sdelements

Status
Vendor
CVE Published:
28 July 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-66751?

The vulnerability present in Let's Chat versions 0.3.0 through 0.4.8 allows any authenticated user to archive any room on the server via an unrestricted DELETE request to the rooms handler, bypassing necessary ownership checks. This exploitation lets malicious users permanently remove access to private or password-protected rooms, posing a significant risk as there is no application-level mechanism for recovery. Restoring archived rooms would necessitate direct database intervention, escalating the risk for data loss and unauthorized actions.

Affected Version(s)

lets-chat 0.3.0 <= 0.4.8

lets-chat 0.3.0 <= 0.4.8

lets-chat 5b5f46f92696955c27864dbca8b33b5b6a39a502 <= 617207ff3c0c0bf8e3c7a915bd9ec03f1dd8390c

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Theodosis Paidakis
.