What is CVE-2026-70617?
'Spacebar Server' versions prior to commit dcfd910 contain a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the 'channels recipient endpoint' without membership verification. This flaw could lead to unauthorized access to group conversations. Users are advised to immediately update to the specified commit or later.
Azərbaycanca: 'Spacebar Server'in dcfd910 commit'ə qədərki versiyalarında identifikasiya olunmuş istənilən şəxsə, 'channels recipient endpoint'ə PUT sorğusu göndərərək icazə yoxlaması olmadan özlərini istənilən qrup DM kanalına əlavə etməyə imkan verən 'missing authorization' zəifliyi mövcuddur. Bu boşluq qrup söhbətlərinə icazəsiz girişə səbəb ola bilər. İstifadəçilərə dərhal proqramı göstərilən commit və ya daha sonrakı versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Does exploiting CVE-2026-70617 require the attacker to be authenticated on Spacebar Server?
Yes, this vulnerability can only be exploited by any authenticated attacker. Once logged into the system, they can add themselves to arbitrary group DM channels without membership verification.
Which component of Spacebar Server does CVE-2026-70617 target?
This flaw targets the authorization check mechanism by sending a PUT request to the 'channels recipient endpoint', allowing an attacker to gain unauthorized access to group conversations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.