


Perceptive Security
SOC/SIEM Consultancy

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group…
Published:
4 augustus 2026 om 22:00:00
Alert date:
5 augustus 2026 om 21:03:13
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Email & Messaging
Spacebar Server before commit dcfd910 contains a missing authorization vulnerability tracked as CVE-2026-70617. Any authenticated attacker can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} endpoint to add themselves to arbitrary group DM channels without membership verification. The vulnerability allows attackers to join private group DMs, read complete message history, post messages as a participant, and force-add third-party users without their consent. The fix was introduced in commit dcfd91035e3da42abf5f32d8d86a35219225b3d4. The issue is documented in a GitHub security advisory (GHSA-g38j-78fh-jm74) and VulnCheck. It represents a significant privacy and integrity risk for all users of affected Spacebar Server deployments. Users should update to the patched commit immediately to mitigate exposure.
Technical details
Mitigation steps:
Affected products:
Spacebar Server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-70617
https://github.com/spacebarchat/server/commit/dcfd91035e3da42abf5f32d8d86a35219225b3d4
https://github.com/spacebarchat/server/security/advisories/GHSA-g38j-78fh-jm74
https://www.vulncheck.com/advisories/spacebar-server-missing-authorization-via-group-dm-recipient-endpoint
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
