# CVE-2026-24332

## Summary

- **CVE ID:** CVE-2026-24332
- **Severity:** MEDIUM
- **CVSS Score:** 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **CWE:** CWE-204
- **Published:** Jan 22, 2026
- **Last Modified:** Sep 12, 2026

## Description

Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omitted from the presences array. This is arguably inconsistent with the UI description of Invisible as "You will appear offline."

## Affected Products

- Discord — WebSocket API service (0)

## References

- [CNA](https://xmrcat.org/discord-invisibility-bypass)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.28%
- **EPSS Percentile:** 20.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._