Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to the rooms handler without ownership verification. Attackers can enumerate room IDs via the rooms listing endpoint and permanently archive private or password-protected rooms they cannot access, with no application-level recovery path requiring direct database intervention to restore.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66751.json",
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-862"
],
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "5b5f46f92696955c27864dbca8b33b5b6a39a502"
},
{
"last_affected": "617207ff3c0c0bf8e3c7a915bd9ec03f1dd8390c"
}
],
"source": "AFFECTED_FIELD"
}
]
}