CVE-2026-48007

element-hq · element-call

Element Call contains an information exposure vulnerability that allows an authenticated attacker to access sensitive data.

Executive summary

A high-severity information exposure vulnerability in Element Call allows authenticated attackers to access sensitive data, necessitating an immediate update.

Vulnerability

The application is susceptible to an exposure of sensitive information (CWE-200) due to insufficient access controls. This vulnerability requires the attacker to have low-level privileges (authenticated) to successfully exploit the flaw.

Business impact

Successful exploitation of this vulnerability could lead to unauthorized access to sensitive communications or private data processed within the video conferencing platform. Given the CVSS score of 8.6, the risk to confidentiality and integrity is significant, potentially resulting in data breaches or unauthorized information disclosure.

Remediation

Immediate Action: Administrators must update the @element-hq/element-call-embedded package to version 0.19.4 or later.

Proactive Monitoring: Security teams should monitor logs for unusual access patterns or unauthorized attempts to retrieve session-specific information.

Compensating Controls: Ensure that existing network-level access controls are strictly enforced to limit the exposure of the application to only authorized users.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the high CVSS score and the potential for sensitive data exposure, it is critical that organizations prioritize the deployment of the 0.19.4 update. Failure to patch may expose internal communications to unauthorized actors.