CVE-2026-63095

Source
https://cve.org/CVERecord?id=CVE-2026-63095
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63095.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63095
Published
2026-07-17T15:27:44.640Z
Modified
2026-07-19T03:46:37.487268993Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint
Details

Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account deletion endpoint without ownership verification. Attackers can exploit the unverified Forget3PID handler to remove a victim's email or MSISDN binding and subsequently rebind the address through an identity server to hijack the victim's password reset flow.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63095.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ]
}
References

Affected packages

Git / github.com/matrix-org/dendrite

Affected ranges

Type
GIT
Repo
https://github.com/matrix-org/dendrite
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.13.8"
        }
    ]
}

Affected versions

helm-dendrite-0.*
helm-dendrite-0.10.8
helm-dendrite-0.10.9
helm-dendrite-0.11.0
helm-dendrite-0.11.1
helm-dendrite-0.11.2
helm-dendrite-0.12.0
helm-dendrite-0.12.1
helm-dendrite-0.12.2
helm-dendrite-0.12.3
helm-dendrite-0.12.4
helm-dendrite-0.13.0
helm-dendrite-0.13.1
helm-dendrite-0.13.2
helm-dendrite-0.13.3
helm-dendrite-0.13.4
helm-dendrite-0.13.5
helm-dendrite-0.13.6
helm-dendrite-0.13.7
helm-dendrite-0.13.8
helm-dendrite-0.14.0
helm-dendrite-0.14.1
helm-dendrite-0.14.2
v0.*
v0.1.0
v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.10.6
v0.10.7
v0.10.8
v0.10.9
v0.11.0
v0.11.1
v0.12.0
v0.13.0
v0.13.1
v0.13.2
v0.13.3
v0.13.4
v0.13.5
v0.13.6
v0.13.7
v0.13.8
v0.2.0
v0.2.1
v0.3.0
v0.3.1
v0.3.10
v0.3.11
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.7
v0.3.8
v0.3.9
v0.4.0
v0.4.1
v0.5.0
v0.5.0rc1
v0.5.1
v0.6
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.7.0
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.3rc1
v0.8.4
v0.8.5
v0.8.6
v0.8.7
v0.8.8
v0.8.9
v0.9.0
v0.9.1
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63095.json"