CVE-2026-104480
Received Received - Intake

Discord libdave MLS Welcome Message Unauthorized Participant

Vulnerability report for CVE-2026-104480, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Bugcrowd Inc.

Description

Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
discord libdave to 1.2.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-390 The product detects a specific error, but takes no actions to handle the error.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Discord's libdave library before version 1.2.0 failing to properly validate MLS Welcome messages. An attacker controlling the DAVE signaling path could manipulate messages to add unauthorized participants to an end-to-end encrypted media session. This bypasses security controls and allows interception or manipulation of audio and video communications.

Detection Guidance

This vulnerability involves improper validation of MLS Welcome messages in Discord's libdave library. Detection requires checking if your system uses a vulnerable version of libdave (before 1.2.0). Inspect installed versions via package managers or library files. Monitor network traffic for unexpected MLS Welcome messages with unrecognized participants.

Impact Analysis

If exploited, this vulnerability could allow unauthorized individuals to join private voice or video calls without detection. This compromises the confidentiality and integrity of your communications, potentially exposing sensitive conversations to eavesdroppers or malicious participants.

Compliance Impact

This vulnerability could lead to unauthorized access to protected communications, violating data confidentiality requirements under GDPR and HIPAA. Organizations using affected Discord clients may face compliance violations, legal liabilities, and reputational damage due to potential exposure of sensitive personal or health information.

Mitigation Strategies

Update libdave to version 1.2.0 or later immediately. This version restores strict validation of MLS Welcome states, rejecting unauthorized participants. Verify the update by checking library versions and restarting affected Discord clients. Ensure all clients and servers are patched to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104480. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart