CVE-2026-45057
Last modified
CVE-2026-45057 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrators (or actors with equivalent power) to impersonate or spoof messages as if they were sent by a victim user. `matrix-sdk-ui` 0.17.0 fixes the message edit validation logic to align with the algorithm for replacement events[^1] described in the Matrix specification. No known workarounds are available.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| matrix-org | matrix-sdk-ui | < 0.16.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-45057?
How severe is CVE-2026-45057?
How do I fix CVE-2026-45057?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-45051Open Access Management (OpenAM) is an access management solu…9.2
- CVE-2026-45052Open Access Management (OpenAM) is an access management solu…9.3
- CVE-2026-45053CubeCart is an ecommerce software solution. Prior to 6.7.0, …9.1
- CVE-2026-45054CubeCart is an ecommerce software solution. Prior to 6.7.0, …4.9
- CVE-2026-45055CubeCart is an ecommerce software solution. Prior to 6.7.2, …8.1
- CVE-2026-45056matrix-sdk-crypto is a no-network-IO implementation of a sta…6.9
- CVE-2026-45058electerm is an open-sourced terminal/ssh/sftp/telnet/serialp…9.4
- CVE-2026-4506A vulnerability was found in Mindinventory MindSQL up to 0.2…6.3
- CVE-2026-45060ClipBucket v5 is an open source video sharing platform. Prio…9.8
- CVE-2026-45061Budibase is an open-source low-code platform. Prior to 3.35.…7.7
- CVE-2026-45062FrankenPHP is a modern application server for PHP. From vers…8.1
- CVE-2026-45063Symfony is a PHP framework for web and console applications …9.1
Are you affected by CVE-2026-45057?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
