CVE-2017-0910: Zulip Server

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.

Affected products

  • Zulip Zulip Server: before 1.7.1 (fixed in 1.7.1)

Published 2017-11-27. Last modified 2026-06-17.