CVE-2026-46712
LOWMisskey: Lack of proper permission checks in Direct Messaging feature
Title source: cnaDescription
Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Messages (formerly Chat) feature, regardless of account permissions. This vulnerability occurs whether or not federation is enabled. Notes created with "specified" visibility (formerly "direct" visibility) are not affected. This issue has been fixed in version 2026.5.4.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/misskey-dev/misskey/security/advisories/GHSA-2m3r-xx7x-63j6
X_Refsource_Misc x_refsource_misc
https://github.com/misskey-dev/misskey/releases/tag/2026.5.4
Scores
CVSS v4
2.3
EPSS
0.0022
EPSS Percentile
12.1%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
misskey-dev/misskey
>= 2025.3.2, < 2026.5.4
Published
Aug 03, 2026
Tracked Since
Aug 04, 2026