CVE-2026-82906

Summary

A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File Download Endpoint. This manipulation causes missing authentication. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
sdcbchats1.0affected
sdcbchats1.1affected
sdcbchats1.2affected
sdcbchats1.3affected
sdcbchats1.4affected
sdcbchats1.5affected
sdcbchats1.6affected
sdcbchats1.7affected
sdcbchats1.8affected
sdcbchats1.9affected
sdcbchats1.10affected
sdcbchats1.11affected
sdcbchats1.12.0affected

Weaknesses

  • CWE-306: Missing Authentication
  • CWE-287: Improper Authentication

References