CVE-2026-70618
MEDIUMSpacebar Server Missing Authorization via member-ids Endpoint
Title source: cnaDescription
Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids endpoint without guild membership verification. Attackers can exploit the unprotected route handler in the roles member-ids endpoint, which lacks permission checks present in sibling endpoints, to retrieve the full list of member user IDs for any guild on the instance using only a valid bearer token and a known guild ID.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-p5cf-7hg9-gf65)
https://github.com/spacebarchat/server/security/advisories/GHSA-p5cf-7hg9-gf65
Patch patch
Patch Commit
https://github.com/spacebarchat/server/commit/51da17cf19d476483ee44e5f832d1ebdcd844f88
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/spacebar-server-missing-authorization-via-member-ids-endpoint
Scores
CVSS v3
4.3
EPSS
0.0019
EPSS Percentile
9.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (1)
Spacebar Server/Spacebar Server
< 51da17cf19d476483ee44e5f832d1ebdcd844f88
Published
Aug 05, 2026
Tracked Since
Aug 06, 2026