CVE-2026-42889: Relay Server WebSocket authentication bypass when token is omitted
Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured, WebSocket connections without a token query parameter were incorrectly treated as having full server permissions. An unauthenticated network attacker who knows or guesses a document ID could connect to the document sync WebSocket and read or modify document contents without a valid document token. This vulnerability is fixed in 0.9.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42889?
CVE-2026-42889 is considered a high severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2026-42889?
To fix CVE-2026-42889, update to Relay Server version 0.9.7 or later where the vulnerability has been addressed.
What versions of Relay Server are affected by CVE-2026-42889?
Relay Server versions 0.9.0 through 0.9.6 are affected by CVE-2026-42889.
What type of vulnerability is CVE-2026-42889?
CVE-2026-42889 is an authentication bypass vulnerability in the WebSocket endpoints of Relay Server.
Can CVE-2026-42889 be exploited remotely?
Yes, CVE-2026-42889 can be exploited remotely since it allows unauthenticated WebSocket connections.