CVE-2026-104480: Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership

Published Oct 2, 2026
·
Updated

Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.

Affected Software

1 affected component
Discord libdave<1.2.0

Event History

Oct 2, 2026
CVE Published
via MITRE·12:57 AM
Data Sourced
via MITRE·12:57 AM
DescriptionWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Clients using Discord libdave versions before 1.2.0 are affected. The issue concerns clients participating in end-to-end encrypted audio or video sessions that process MLS Welcome messages.

2

What level of attacker access is needed to exploit it?

An attacker must control the DAVE signaling path, such as the voice gateway, or hold an equivalent position that lets them add, alter, or withhold signaling messages sent to a client. No client-side privileges or user interaction are required according to the supplied CVSS vector.

3

What is the practical impact of successful exploitation?

Affected clients can accept an unauthorized participant into an end-to-end encrypted media session. This can compromise the confidentiality and integrity of session audio and video.

4

What should teams do to remediate the issue?

Update Discord libdave to version 1.2.0 or later. The release information and referenced commit identify version 1.2.0 as the version containing the roster-validation correction.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203