Authorization Bypass in OpenIM Server Affects User Management Features
CVE-2026-69115

7.1HIGH

Key Information:

Vendor

Openimsdk

Vendor
CVE Published:
11 August 2026

What is CVE-2026-69115?

OpenIM Server v3.8.3 is prone to a missing authorization vulnerability, allowing any authenticated user to access sensitive admin management API endpoints. This flaw permits attackers to utilize standard user bearer tokens to submit POST requests to endpoints like /user/get_users, /user/get_all_users_uid, and /group/get_groups. The lack of internal authorization checks enables unauthorized access to user account details, including userIDs, nicknames, and managerial flags, as well as sensitive group information—such as private group identifiers, member counts, and ownership details—potentially leading to significant privacy violations and exploitation.

Affected Version(s)

OpenIM Server (open-im-server) 0 <= 3.8.3

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.