CVE-2026-24332
Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omitted from the presences array. This is arguably inconsistent with the UI description of Invisible as "You will appear offline."
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.28%
- CWE
- CWE-204
- Published
- 2026-01-22
- Last modified
- 2026-09-12
Affected products
- Discord WebSocket API service
Weakness type
Related vulnerabilities
- CVE-2026-33419 — MinIO: LDAP login brute-force via user enumeration and missing rate limit
- CVE-2025-5485 — SinoTrack GPS Receiver Weak Authentication
- CVE-2018-25350 — userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
- CVE-2026-6207 — Observable response discrepancy vulnerability in HAVELSAN Inc. Geographic Tracking System allows System Footprinting. T
- CVE-2026-60007 — In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P
- CVE-2026-15747 — Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle
- CVE-2021-34580 — Remote user enumeration in mymbCONNECT24, mbCONNECT24 <= 2.9.0
- CVE-2025-46390 — CWE-204: Observable Response Discrepancy