Executive brief
HumHub, an open-source enterprise social network, contains a security flaw in how it manages group (Space) memberships. An authenticated user could exploit this flaw to remove every member from any group on the platform, even if they are not a member or administrator of that group. This could lead to significant operational disruption, loss of collaboration data, and unauthorized modification of social structures within the organization.
Technical details
A missing authorization check (CWE-862) exists within the Space member management controller of HumHub. The vulnerability allows any user with a valid account to invoke the 'remove all members' action against any Space ID, bypassing intended role-based access controls. This is a network-reachable flaw requiring only low-level 'user' privileges. Successful exploitation results in the mass removal of users from the targeted Space, impacting the integrity of the social network's organizational structure. The issue is resolved in version 1.18.3 by implementing proper permission validation in the affected controller.
Affected products
- HumHub HumHub 1.13.0 - 1.18.2
Timeline
- 2026-05-18: patched: Fix PR merged into master branch
- 2026-05-19: advisory: GitHub Security Advisory published
- 2026-07-21: disclosed: CVE published to NVD