CVE-2025-32026

LOW

Element Web <1.11.96 - Info Disclosure

Title source: llm
STIX 2.1

Description

Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to version 1.11.96, can be configured to load Element Call from an external URL. Under certain conditions, the external page is able to get access to the media encryption keys used for an Element Call call. Version 1.11.97 fixes the problem.

Scores

CVSS v3 3.8
EPSS 0.0013
EPSS Percentile 32.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-497
Status published
Products (1)
element-hq/element-web >= 1.11.16, < 1.11.97
Published Apr 08, 2025
Tracked Since Feb 18, 2026