Authorization Bypass in OpenIM Server Affects User Management Features
CVE-2026-69115
7.1HIGH
What is CVE-2026-69115?
OpenIM Server v3.8.3 is prone to a missing authorization vulnerability, allowing any authenticated user to access sensitive admin management API endpoints. This flaw permits attackers to utilize standard user bearer tokens to submit POST requests to endpoints like /user/get_users, /user/get_all_users_uid, and /group/get_groups. The lack of internal authorization checks enables unauthorized access to user account details, including userIDs, nicknames, and managerial flags, as well as sensitive group information—such as private group identifiers, member counts, and ownership details—potentially leading to significant privacy violations and exploitation.
Affected Version(s)
OpenIM Server (open-im-server) 0 <= 3.8.3
