Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership
Summary
| CVE | CVE-2026-104480 |
|---|---|
| State | PUBLISHED |
| Assigner | Bugcrowd |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-02 02:17:02 UTC |
| Updated | 2026-10-02 02:17:02 UTC |
| Description | Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video. |
Risk And Classification
Primary CVSS: v4.0 9.4 CRITICAL from 4ac701fe-44e9-4bcd-9585-dd6449257611
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-390 | CWE-863 | CWE-390 CWE-390 Detection of Error Condition Without Action | CWE-863 CWE-863 Incorrect Authorization
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 4ac701fe-44e9-4bcd-9585-dd6449257611 | Secondary | 9.4 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 9.4 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
PresentPrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
NoneSub Conf.
HighSub Integrity
HighSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| daveprotocol.com | 4ac701fe-44e9-4bcd-9585-dd6449257611 | daveprotocol.com | |
| github.com/discord/libdave/releases/tag/v1.2.0/cpp | 4ac701fe-44e9-4bcd-9585-dd6449257611 | github.com | |
| github.com/discord/libdave | 4ac701fe-44e9-4bcd-9585-dd6449257611 | github.com | |
| github.com/discord/libdave/commit/9686fbaea864aa19f0675e486672b6a77811b6a1 | 4ac701fe-44e9-4bcd-9585-dd6449257611 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: MDL (https://heartbreak.ing) (en)
There are currently no legacy QID mappings associated with this CVE.