{"id":"CVE-2018-12423","aliases":["GHSA-ch5v-fhg8-7gv9","PYSEC-2026-844"],"url":"https://o3.security/vulnerability/CVE-2018-12423","summary":"Matrix Synapse Authorization Error","details":"In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.","published":"2018-06-14T21:29:00.253Z","modified":"2026-07-08T14:14:24.585927Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"matrix-synapse","fixedVersion":"0.31.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://bugs.debian.org/901549"},{"type":"ADVISORY","url":"https://github.com/matrix-org/matrix-doc/issues/1304"},{"type":"ADVISORY","url":"https://matrix.org/blog/2018/06/14/security-update-synapse-0-31-2/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T14:14:24.585927Z"}}