CVE-2026-108730
Received Received - Intake

Raven Missing Authorization in Legacy Methods Exposes Channel Data

Vulnerability report for CVE-2026-108730, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Raven 2.0.0 through 3.0.0 contains a missing authorization vulnerability in legacy methods in raven/api/raven_message.py that skip the workspace membership check. Authenticated non-members can call get_messages_with_dates or get_all_files_shared_in_channel with predictable channel IDs to read Public channel history and Open/Public channel file metadata across workspaces.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
The-Commit-Company raven 2.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Raven versions 2.0.0 through 3.0.0 contain a missing authorization vulnerability in legacy methods in raven/api/raven_message.py. These methods, get_messages_with_dates and get_all_files_shared_in_channel, skip workspace membership checks. Authenticated non-members can exploit predictable channel IDs to read public channel message history and file metadata from open or public channels across workspaces.

Detection Guidance

Check Raven API logs for unusual access patterns to /api/method/raven.api.raven_message.get_messages_with_dates or /api/method/raven.api.raven_message.get_all_files_shared_in_channel endpoints. Look for requests from non-workspace members or repeated calls with predictable channel IDs.

Impact Analysis

An authenticated attacker who is not a workspace member could access sensitive data. This includes reading public channel messages and viewing file metadata (names, URLs, sizes, owners) from open or public channels. The attack is possible due to predictable channel IDs and lack of proper authorization checks.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating privacy regulations like GDPR or HIPAA. Exposure of message history and file metadata in public or open channels may result in non-compliance with data protection requirements, especially if the data includes personal or confidential information.

Mitigation Strategies

Upgrade Raven to the latest version beyond 3.0.0 where legacy endpoints are removed or fixed. Temporarily restrict access to the vulnerable API endpoints via firewall rules or reverse proxy until patched. Review logs for past unauthorized access and notify affected workspace members.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108730. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart