CVE-2026-47657: HumHub Missing Authorization on Remove All Space Members Action
HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regardless of their own role or membership in that Space. Versions 1.13.0 through 1.18.2 are affected. The vulnerability has been patched in version 1.18.3, and all users are encouraged to upgrade to this version or later immediately. No known workaround is available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
humhubto a version that resolves this vulnerability.Fixed in 1.18.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47657?
CVE-2026-47657 has a severity rating of high with a CVSS score of 7.1.
How do I fix CVE-2026-47657?
To fix CVE-2026-47657, upgrade your HumHub installation to version 1.18.3 or later.
What is the impact of CVE-2026-47657?
CVE-2026-47657 allows any authenticated user to remove all members from any Space without proper authorization.
In which versions is CVE-2026-47657 applicable?
CVE-2026-47657 affects HumHub versions from 1.13.0 through 1.18.2.
Who is affected by CVE-2026-47657?
Any user with authentication in HumHub can exploit CVE-2026-47657 if the affected versions are in use.