CVE-2026-45057
matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrators (or actors with equivalent power) to impersonate or spoof messages as if they were sent by a victim user. `matrix-sdk-ui` 0.17.0 fixes the message edit validation logic to align with the algorithm for replacement events[^1] described in the Matrix specification. No known workarounds are available.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- EPSS probability
- 0.15%
- CWE
- CWE-345
- Published
- 2026-09-11
- Last modified
- 2026-09-14
Affected products
- matrix-org matrix-sdk-ui
Weakness type
Related vulnerabilities
- CVE-2026-44523 — Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
- CVE-2026-48781 — Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
- CVE-2026-80172 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-28185 — WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability
- CVE-2026-53513 — Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
- CVE-2026-33471 — nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
- CVE-2026-45058 — electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark
- CVE-2026-44592 — Gradient: Unauthenticated worker on /proto → arbitrary NAR write / cache poisoning