Missing Authorization in Spacebar Server Allows Unrestricted Access to Group DM Channels
CVE-2026-70617

8.6HIGH

Key Information:

Vendor
CVE Published:
5 August 2026

What is CVE-2026-70617?

Spacebar Server contains a vulnerability that permits authenticated attackers to exploit a missing authorization mechanism. By sending a PUT request to the group's recipient endpoint, attackers can add themselves and others to private group DM channels. This allows them to read message history, post messages as legitimate participants, and potentially add third-party users without their consent. The lack of membership verification poses significant risks to the privacy and security of communications within these channels.

Affected Version(s)

Spacebar Server 0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.