What is CVE-2026-66750?
Let's Chat versions 0.3.0 through 0.4.8 contain a broken access control vulnerability in the file retrieval route. Authenticated attackers can download file attachments from private and password-protected rooms they are not members of, due to missing room membership checks. Upgrading to the latest version is strongly recommended to prevent unauthorized access to sensitive files.
Azərbaycanca: Let's Chat 0.3.0-dan 0.4.8-ə qədər versiyalarda 'broken access control' zəifliyi aşkar edilib. Doğrulanmış istifadəçi, üzv olmadığı gizli və parolla qorunan otaqlardakı fayl əlavələrini, fayl əldəetmə marşrutunda otaq üzvlüyü yoxlamasının olmaması səbəbindən yükləyə bilər. Təsirə məruz qalan sistemlərdə həssas sənədlərin sızmasının qarşısını almaq üçün dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What files can be accessed without authorization by exploiting CVE-2026-66750?
An authenticated attacker can download file attachments from private and password-protected rooms they are not members of.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.