EUVD Vulnerability Catalog
EUVD-2026-91159
Severity: CRITICAL
Base Score: 9.4
CVSS Version: 4.0
Vulnerability Description
Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Attack Requirements (AT): Present
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Vulnerability Confidentiality Impact (VC): High
▪
Vulnerability Integrity Impact (VI): High
▪
Vulnerability Availability Impact (VA): None
▪
Subsequent Confidentiality Impact (SC): High
▪
Subsequent Integrity Impact (SI): High
▪
Subsequent Availability Impact (SA): None
Affected Vendors & Systems
Vendor
Discord
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
Bugcrowd
EPSS Probability
0
Known Aliases
CVE-2026-104480
GHSA-3q99-x36r-rchh
Published On
2026-10-02
Last Updated
2026-10-02