PT-2026-60788 · Git+1 · Dendrite

·

CVE-2026-63095

·

Published

2026-07-17

·

Updated

2026-07-17

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Dendrite versions prior to 0.13.9
Description An improper authorization issue exists in the Matrix Client-Server API. An authenticated local user can delete third-party identifier bindings of other users by submitting an arbitrary address and medium to the account deletion endpoint, as the system fails to verify ownership. This occurs via the unverified Forget3PID handler, allowing an attacker to remove a victim's email or MSISDN (Mobile Station International Subscriber Directory Number, a unique identifier for mobile devices) binding. Consequently, the attacker can rebind the address through an identity server to hijack the password reset process.
Recommendations Update to version 0.13.9 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63095

Affected Products

Dendrite