Junglewise Threat Intelligence

CVE-2026-25742: Zulip missing authorization for anonymous access to attachments and topics

CVE-2026-25742 · Severity: medium · CVSS 5.3 · Published 2026-04-03

Executive brief

Zulip is an open-source team collaboration platform. A security flaw allowed unauthorized users to access files and chat topic histories even after administrators had disabled public 'spectator' access. This means that sensitive documents or conversation titles intended to be private could still be viewed by anyone on the internet without logging in.

Technical details

A missing authorization check (CWE-862) in Zulip's attachment and topic history endpoints allows for unauthorized data retrieval. Specifically, the 'validate_attachment_request_for_spectator_access' function and the '/users/me/<stream_id>/topics' endpoint failed to verify the 'allow_web_public_streams_access()' realm setting. Consequently, even if an administrator disables spectator access (WEB_PUBLIC_STREAMS_ENABLED), files and topic metadata from previously public streams remain accessible to unauthenticated remote attackers via direct URL access. This issue was introduced in Zulip 5.0 and is patched in version 11.6.

Affected products

  • Zulip Zulip 1.4.0 to 11.5

Timeline

  • 2026-03-31: patched: Fixed in version 11.6
  • 2026-04-03: disclosed: Initial NVD publication

References

Related threats