Vulnerability Description
Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to version 1.11.96, can be configured to load Element Call from an external URL. Under certain conditions, the external page is able to get access to the media encryption keys used for an Element Call call. Version 1.11.97 fixes the problem.
CVSS Score
LOW
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-32026?
CVE-2025-32026 is a vulnerability with a CVSS score of 3.8 (LOW). Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to version 1.11.96, can be configured to load Element Call from an external URL. Unde...
How severe is CVE-2025-32026?
CVE-2025-32026 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-32026?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.