What is CVE-2026-48007?
CVE-2026-48007 affects Element Call versions 0.5.17 through 0.19.3, where analytics data sent to a PostHog server may leak sensitive fields (like $initial_person). This vulnerability increases user privacy risk, so updating to the latest version is recommended.
Azərbaycanca: CVE-2026-48007 zəifliyi Element Call tətbiqinin 0.5.17-dən 0.19.3-ə qədər versiyalarına təsir edir, burada PostHog analitika serverinə göndərilən məlumatlarda həssas sahələr ($initial_person kimi) sıza bilər. Bu zəiflik istifadəçi məxfilik riskini artırır, ona görə də tətbiqi ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of Element Call are affected by CVE-2026-48007?
This vulnerability affects Element Call versions 0.5.17 through 0.19.3.
What is the primary risk of CVE-2026-48007?
The primary risk is increased user privacy exposure due to leakage of sensitive fields like $initial_person in data sent to a PostHog analytics server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.