CVE-2026-104480 CRITICAL

CVE-2026-104480: Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership

Vendor Discord
Product libdave
Weakness CWE-390
Published October 2, 2026
Last update October 2, 2026

CVSS base score

9.4/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

What the vulnerability does

01Description

Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video.

Key dates

02Disclosure timeline

October 2, 2026 CVE published