OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-104480

CRITICAL · CVSS 9.4 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects Discord's libdave library prior to version 1.2.0, allowing an attacker with control over the DAVE signaling path to introduce an unauthorized participant into an end-to-end encrypted media session. This can lead to a severe compromise of both the confidentiality and integrity of audio and video communications. Organizations utilizing affected versions of the library should prioritize immediate updates to mitigate the risk of unauthorized access to sensitive media sessions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104480
Severity
CRITICAL
CVSS
9.4
EPSS
0.40%

Original NVD Description

Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.