CVE-2026-63095
Last modified
CVE-2026-63095 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account deletion endpoint without ownership verification. Attackers can exploit the unverified Forget3PID handler to remove a victim's email or MSISDN binding and subsequently rebind the address through an identity server to hijack the victim's password reset flow..
Description
Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account deletion endpoint without ownership verification. Attackers can exploit the unverified Forget3PID handler to remove a victim's email or MSISDN binding and subsequently rebind the address through an identity server to hijack the victim's password reset flow.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| matrix-org | dendrite | <= 0.13.8 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-63095?
How severe is CVE-2026-63095?
How do I fix CVE-2026-63095?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6309Use after free in Viz in Google Chrome prior to 147.0.7727.1…8.3
- CVE-2026-63090ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based bu…8.8
- CVE-2026-63091ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed intege…7.1
- CVE-2026-63092kirby-modules through 5.5.7, fixed in commit 315417e, contai…5.3
- CVE-2026-63093Cursor for Windows version 3.2.16 contains a binary planting…8.8
- CVE-2026-63094SigNoz before 0.134.0 contains an open redirect vulnerabilit…8.1
- CVE-2026-63096Dendrite through 0.13.8 contains a server-side request forge…6.9
- CVE-2026-63097Dendrite through 0.13.8 contains an improper access control …5.3
- CVE-2026-63098TheHive through 4.1.24 contains an unauthenticated informati…6.9
- CVE-2026-63099TheHive through 4.1.24 contains a broken object-level author…7.1
- CVE-2026-6310Use after free in Dawn in Google Chrome prior to 147.0.7727.…8.3
- CVE-2026-63100Maybe through 0.6.0 contains a missing authorization vulnera…7.1
Are you affected by CVE-2026-63095?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
