Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video. | |
| Title | Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership | |
| Weaknesses | CWE-390 CWE-863 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Bugcrowd
Published:
Updated: 2026-10-02T00:57:55.648Z
Reserved: 2026-10-02T00:57:11.860Z
Link: CVE-2026-104480
No data.
Status : Received
Published: 2026-10-02T02:17:02.007
Modified: 2026-10-02T02:17:02.007
Link: CVE-2026-104480
No data.
OpenCVE Enrichment
Updated: 2026-10-02T02:30:18Z
