๐Ÿ” CVE Alert

CVE-2026-70617

HIGH 8.1

Spacebar Server Missing Authorization via Group DM Recipient Endpoint

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} handler to join private group DMs, read complete message history, post messages as a participant, and force-add third-party users without their consent.

CWE CWE-862
Vendor spacebar server
Product spacebar server
Published Aug 5, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for spacebar server spacebar server

Be the first to know when new high vulnerabilities affecting spacebar server spacebar server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Spacebar Server / Spacebar Server
0 โ‰ค dcfd91035e3da42abf5f32d8d86a35219225b3d4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/spacebarchat/server/security/advisories/GHSA-g38j-78fh-jm74 github.com: https://github.com/spacebarchat/server/commit/dcfd91035e3da42abf5f32d8d86a35219225b3d4 vulncheck.com: https://www.vulncheck.com/advisories/spacebar-server-missing-authorization-via-group-dm-recipient-endpoint

Credits

George Chen