What is CVE-2026-69114?
CVE-2026-69114 is a cross-channel message deletion vulnerability in Spacebar Server before commit 8d126f4, where single-delete and bulk-delete handlers fail to scope message queries to the requested channel. Authenticated users with MANAGE_MESSAGES permission in any channel can delete arbitrary messages, and affected users should update to commit 8d126f4.
Azərbaycanca: CVE-2026-69114 Spacebar Server-də (commit 8d126f4-dən əvvəlki versiyalarda) çarpaz kanal mesaj silmə zəifliyidir, burada single-delete və bulk-delete funksiyaları sorğuları yalnız tələb olunan kanalla məhdudlaşdırmır. İstənilən kanalda MANAGE_MESSAGES icazəsi olan autentifikasiya olunmuş istifadəçi arzuolunmaz mesajları silə bilər, təsirlənən istifadəçilər commit 8d126f4-ə yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What software is affected by CVE-2026-69114?
CVE-2026-69114 affects Spacebar Server.
Who can exploit CVE-2026-69114?
Authenticated users with MANAGE_MESSAGES permission in any channel can exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.