CVE-2026-46712
Received Received - Intake

Improper Access Control in Misskey Direct Messages Feature

Vulnerability report for CVE-2026-46712, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: GitHub, Inc.

Description

Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Messages (formerly Chat) feature, regardless of account permissions. This vulnerability occurs whether or not federation is enabled. Notes created with "specified" visibility (formerly "direct" visibility) are not affected. This issue has been fixed in version 2026.5.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misskey misskey From 2025.3.2 (inc) to 2026.5.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Misskey (versions 2025.3.2 to before 2026.5.4) allows unauthorized access to certain Direct Messages data due to missing permission checks. Notes with 'specified' visibility are not affected.

Impact Analysis

An attacker could potentially read Direct Messages data even without proper account permissions. This could lead to exposure of private conversations or sensitive information shared via the platform.

Compliance Impact

This vulnerability may violate data protection regulations like GDPR or HIPAA by allowing unauthorized access to private communications. Organizations using affected versions could face compliance violations and legal risks.

Mitigation Strategies

Update Misskey to version 2026.5.4 or later to address the vulnerability. Check for unauthorized access to Direct Messages data and review permission settings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46712. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart