External risk intelligence

Discord libdave Unauthorized Participant Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-104480

The vulnerability exists within a specific client-side library (libdave) used for end-to-end encryption in voice/video sessions. It is not an internet-facing service, gateway, or management interface, but rather a component embedded within client applications, making public internet exposure of the vulnerable code path in a server-like capacity non-existent.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Discord libdave library could allow an attacker to add an unauthorized member to encrypted voice and video sessions. This could compromise the confidentiality and integrity of communications.

  • Unauthorized members can join encrypted sessions.
  • Protects end-to-end encrypted media session integrity.
  • Confirm if this library is used within the organization.

Attack Path

How an attacker could exploit the issue

An attacker controlling the signaling path for Discord's libdave, such as a voice gateway, can manipulate messages to add an unauthorized participant to an encrypted call. This bypasses security checks, allowing the attacker to eavesdrop on or tamper with the audio and video conversations.

  • Entry requires control over signaling messages.
  • Triggered by sending a specific welcome message.
  • Compromises call confidentiality and integrity.

Live Threat

Current exploitation, exposure, and threat context

An attacker on the DAVE signaling path could add an unauthorized participant to an encrypted voice or video session. This could compromise the confidentiality and integrity of the media stream.

  • Encrypted media sessions.
  • Unrecognized participant in group roster.
  • Compromised confidentiality and integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

The libdave library's handling of unrecognized participants in MLS Welcome messages presents a risk to the confidentiality and integrity of encrypted media sessions. Teams responsible for managing the voice gateway or equivalent signaling path, along with application owners integrating libdave, should prioritize assessing exposure. The immediate first step is to identify all instances of the affected technology, determine their reachability and criticality, and then identify the accountable owner to plan remediation based on risk.

  • Application and platform owners own this issue.
  • Verify signaling path reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the libdave library used for in Discord?

Libdave is a library that implements the Messaging Layer Security (MLS) protocol, which handles end-to-end encryption for voice and video sessions. It ensures that only authorized participants can access the media stream in real-time.

What is the vulnerability in CVE-2026-104480?

This issue is an improper authorization weakness where the software fails to reject MLS Welcome messages containing unrecognized participants. Essentially, the system incorrectly trusts new members added to a group roster, allowing unauthorized parties to potentially enter an encrypted session.

How can an attacker trigger this CVE-2026-104480 flaw?

An attacker must gain control over the signaling path, such as the voice gateway, to alter or inject malicious welcome messages. This flaw is not triggered by standard user activity or public network interaction; it requires specific positioning to manipulate the underlying protocol messages that establish encrypted calls.

Do I need to worry about this if I just use the app?

According to Halo Surface Signal, this vulnerability is very unlikely to affect typical users because it resides in a client-side component rather than an internet-facing server interface. The risk is limited to applications integrating the vulnerable library, not general network services.

What is the first step to address this risk?

You should start by performing an inventory to identify all internal applications or services that integrate the libdave library. Once identified, map out which systems use these components in signaling paths to determine if any environments are susceptible to unauthorized participant entry.

References