What is CVE-2026-66751?
This vulnerability affects Let's Chat versions 0.3.0 through 0.4.8, allowing any authenticated user to archive any room on the server via a DELETE request without ownership verification. Affected systems should be updated to the latest version immediately to prevent unauthorized room archival by attackers.
Azərbaycanca: Bu boşluq Let's Chat plaftformasının 0.3.0-dən 0.4.8 versiyalarına qədər olan aralığında aşkar edilib, istənilən autentifikasiya olunmuş istifadəçiyə sahiblik yoxlaması olmadan serverdəki istənilən otağı arxivləmək imkanı verir. Təsirə məruz qalan sistemlərdə zərərli istifadəçilər DELETE sorğusu göndərərək vacib otaqları sıradan çıxara bilər, buna görə proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of Let's Chat are affected by CVE-2026-66751?
This vulnerability affects Let's Chat versions 0.3.0 through 0.4.8.
What is the root cause of CVE-2026-66751 and how can it be exploited?
The vulnerability allows any authenticated user to archive any room on the server by sending a DELETE request without ownership verification.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.