Security Advisory

CVE-2026-69114

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-10 19:28:49
Last updated 2026-08-11 14:44:44
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers that fail to scope message queries to the requested channel. Authenticated users with MANAGE_MESSAGES permission in any controlled channel can delete arbitrary messages in other channels by routing delete requests through their own channel.