PT-2026-69932 · Unknown · Spacebar Server

·

CVE-2026-69114

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Spacebar Server versions prior to commit 8d126f4
Description Authenticated users possessing the MANAGE MESSAGES permission in a channel they control can delete arbitrary messages in other channels. This occurs because the single-delete and bulk-delete message handlers fail to properly scope message queries to the requested channel, allowing delete requests to be routed through a controlled channel to bypass intended restrictions.
Recommendations Update Spacebar Server to commit 8d126f4 or a later version.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69114
GHSA-62G6-28HV-H6HC

Affected Products

Spacebar Server