CVE-2026-69114: Spacebar Server
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers that fail to scope message queries to the requested channel. Authenticated users with MANAGE_MESSAGES permission in any controlled channel can delete arbitrary messages in other channels by routing delete requests through their own channel.
Affected products
- Spacebar Server Spacebar Server
Published 2026-08-10. Last modified 2026-09-17.