PT-2026-60788 · Git+1 · Dendrite
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Dendrite versions prior to 0.13.9
Description
An improper authorization issue exists in the Matrix Client-Server API. An authenticated local user can delete third-party identifier bindings of other users by submitting an arbitrary address and medium to the account deletion endpoint, as the system fails to verify ownership. This occurs via the unverified
Forget3PID handler, allowing an attacker to remove a victim's email or MSISDN (Mobile Station International Subscriber Directory Number, a unique identifier for mobile devices) binding. Consequently, the attacker can rebind the address through an identity server to hijack the password reset process.Recommendations
Update to version 0.13.9 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dendrite