CVE-2026-104480
CVE-2026-104480 is a critical-severity vulnerability with a CVSS 4.0 base score of 9.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-390.
Key facts
- Severity: Critical (CVSS 4.0 base score 9.4)
- EPSS exploit prediction: 0% (32nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-390
- Published:
- Last modified:
Description
Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.
Frequently asked questions
- What is CVE-2026-104480?
- Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.
- How severe is CVE-2026-104480?
- CVE-2026-104480 has a CVSS 4.0 base score of 9.4, rated critical severity.
- Is CVE-2026-104480 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (32nd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-104480?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-104480 published?
- CVE-2026-104480 was published on 2026-10-02.
References
- https://daveprotocol.com/
- https://github.com/discord/libdave
- https://github.com/discord/libdave/commit/9686fbaea864aa19f0675e486672b6a77811b6a1
- https://github.com/discord/libdave/releases/tag/v1.2.0/cpp
Other CWE-390 vulnerabilities
- CVE-2026-53434 — Critical (CVSS 9.1): Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based…
- CVE-2026-76642 — High (CVSS 7.8): util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks,…
- CVE-2025-46367 — High (CVSS 7.8): Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Detection of Error Condition Without…
- CVE-2024-27919 — High (CVSS 7.5): Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol…
- CVE-2025-26465 — Medium (CVSS 6.8): A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be…
- CVE-2025-27039 — Medium (CVSS 6.6): Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request.