Missing Authorization in Spacebar Server Allows Unrestricted Access to Group DM Channels
CVE-2026-70617
8.6HIGH
What is CVE-2026-70617?
Spacebar Server contains a vulnerability that permits authenticated attackers to exploit a missing authorization mechanism. By sending a PUT request to the group's recipient endpoint, attackers can add themselves and others to private group DM channels. This allows them to read message history, post messages as legitimate participants, and potentially add third-party users without their consent. The lack of membership verification poses significant risks to the privacy and security of communications within these channels.
Affected Version(s)
Spacebar Server 0
