CVE-2026-46712: Misskey: Lack of proper permission checks in Direct Messaging feature
Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Messages (formerly Chat) feature, regardless of account permissions. This vulnerability occurs whether or not federation is enabled. Notes created with "specified" visibility (formerly "direct" visibility) are not affected. This issue has been fixed in version 2026.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
misskeyto a version that resolves this vulnerability.Fixed in 2026.5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46712?
CVE-2026-46712 has a risk score of 40.
How do I fix CVE-2026-46712?
To remediate CVE-2026-46712, upgrade Misskey to version 2026.5.4 or later.
What is the main issue with CVE-2026-46712?
CVE-2026-46712 involves a lack of proper permission checks in the Direct Messaging feature of Misskey.
Which versions of Misskey are affected by CVE-2026-46712?
CVE-2026-46712 affects Misskey versions 2025.3.2 and later, but prior to 2026.5.4.
What data points are exposed due to CVE-2026-46712?
CVE-2026-46712 allows unauthorized access to certain data points from the Direct Messages feature.