CVE-2026-104480: Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership
Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Clients using Discord libdave versions before 1.2.0 are affected. The issue concerns clients participating in end-to-end encrypted audio or video sessions that process MLS Welcome messages.
What level of attacker access is needed to exploit it?
An attacker must control the DAVE signaling path, such as the voice gateway, or hold an equivalent position that lets them add, alter, or withhold signaling messages sent to a client. No client-side privileges or user interaction are required according to the supplied CVSS vector.
What is the practical impact of successful exploitation?
Affected clients can accept an unauthorized participant into an end-to-end encrypted media session. This can compromise the confidentiality and integrity of session audio and video.
What should teams do to remediate the issue?
Update Discord libdave to version 1.2.0 or later. The release information and referenced commit identify version 1.2.0 as the version containing the roster-validation correction.