Beveiligingsadvies

CVE-2026-66751

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-28 15:36:15
Laatst bijgewerkt 2026-07-28 17:23:26
Toegewezen door VulnCheck
CVSS-score 5.4
Status PUBLISHED

Beschrijving

Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to the rooms handler without ownership verification. Attackers can enumerate room IDs via the rooms listing endpoint and permanently archive private or password-protected rooms they cannot access, with no application-level recovery path requiring direct database intervention to restore.