Executive brief
OpenIM Server is an open-source instant messaging platform used for building real-time communication services. A missing authorization check allows any authenticated user to call admin-only API endpoints, enabling unauthorized enumeration of all user accounts and groups—including private groups and sensitive metadata like user IDs and group ownership information—that should be restricted to administrators only.
Technical details
The vulnerability is a missing authorization flaw (CWE-862) in three API handlers: GetPaginationUsers (/user/get_users), GetAllUserID (/user/get_all_users_uid), and GetGroups (/group/get_groups). The root cause is the absence of an authverify.CheckAdmin() call in these handlers, allowing any authenticated user with a regular bearer token to submit POST requests and access these endpoints. An attacker with valid credentials can enumerate all platform user accounts (userIDs, nicknames, manager flags) and groups (including private groups, names, owner IDs, and member counts). The fix has been confirmed in commit 193870b, which enforces admin access verification for these queries. Network reachability and valid user authentication are required; no additional user interaction is needed.
Affected products
- OpenIM Server 3.8.3
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Fix applied in commit 193870b