Vulnerability Description
Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids endpoint without guild membership verification. Attackers can exploit the unprotected route handler in the roles member-ids endpoint, which lacks permission checks present in sibling endpoints, to retrieve the full list of member user IDs for any guild on the instance using only a valid bearer token and a known guild ID.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/spacebarchat/server/commit/51da17cf19d476483ee44e5f832d1ebdcd
- https://github.com/spacebarchat/server/security/advisories/GHSA-p5cf-7hg9-gf65
- https://www.vulncheck.com/advisories/spacebar-server-missing-authorization-via-m
- https://github.com/spacebarchat/server/security/advisories/GHSA-p5cf-7hg9-gf65
FAQ
What is CVE-2026-70618?
CVE-2026-70618 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/ro...
How severe is CVE-2026-70618?
CVE-2026-70618 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-70618?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.