Junglewise Threat Intelligence

CVE-2026-57206: Microsoft SimpleChat missing authentication in plugin validation endpoints

CVE-2026-57206 · Severity: high · CVSS 8.6 · Published 2026-07-16

Vendors: Microsoft.

Executive brief

SimpleChat, an AI conversation platform for document-based collaboration, contained a security flaw where several administrative and plugin management features were accessible without a password. An unauthorized person on the network could potentially view plugin health data, modify global plugin configurations, or tamper with the application's storage state. This could lead to unauthorized changes to how the AI interacts with documents or a disruption of the service.

Technical details

SimpleChat versions prior to 0.241.206 fail to enforce runtime authentication and authorization on several API endpoints located in `application/single_app/plugin_validation_endpoint.py`. While these routes were documented with security metadata via `@swagger_route`, they lacked the necessary `@login_required`, `@user_required`, or `@admin_required` decorators required for actual enforcement. An unauthenticated attacker can reach these endpoints over the network to enumerate plugin types, trigger server-side instantiation with malicious manifests, or invoke the 'repair' logic to modify global plugin metadata and persisted storage. The vulnerability is addressed in version 0.241.206 by adding the appropriate runtime decorators to the affected routes.

Affected products

  • Microsoft SimpleChat < 0.241.206

Timeline

  • 2026-06-17: advisory: GitHub Security Advisory GHSA-g6gr-xp46-hrmj published
  • 2026-06-25: patched: Version 0.250.001 released (includes fix from 0.241.206)
  • 2026-07-16: disclosed: CVE-2026-57206 published to NVD

References

Related threats