Description
Raven 2.0.0 through 3.0.0 contains a missing authorization vulnerability that allows authenticated users to join invite-only Public workspaces by ignoring the can_only_join_via_invite setting. Attackers with the Raven User role can call the join_workspace method to become persistent members, reading and posting in Public and Open channels.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access
Action: Apply Patch
AI Analysis

Impact

Raven 2.0.0 through 3.0.0 contains a missing authorization flaw that permits any authenticated user to join invite‑only public workspaces by bypassing the can_only_join_via_invite setting. The vulnerability is exercised through the join_workspace API endpoint, allowing an attacker with a standard Raven User role to become a persistent member the workspace and read or post in its public channels. The flaw is an example of unacceptable privilege escalation and is mapped to CWE‑862. The impact is the unauthorized disclosure of workspace data to unauthorized users and potential manipulation or spam of public channels.

Affected Systems

The affected products are The‑Commit‑Company’s Raven software, versions 2.0.0 through 3.0.0. No specific sub‑versions or configuration nuances are listed in the CNA data.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that there is no publicly confirmed exploitation at this time. However, the attack requires only authentication and the existence of the Invite‑Only flag; an attacker who can authenticate with any Raven User role can exploit the flaw. Because the vulnerability allows read and write access to public channels, it can lead to data leakage or the insertion of unwanted content. The overall risk is moderate, with a simple, cookie‑based exploit path and no additional mitigations required beyond patching or configuration changes.

Generated by OpenCVE AI on October 11, 2026 at 13:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and deploy the latest Raven release that enforces the can_only_join_via_invite check (e.g., upgrade to a confirmed fix version or apply the patch from commit a732e10f9c8b2ab3446038396e3eea763da617e7).
  • If an upgrade is not immediately possible, restrict the Raven User role from having permission to join workspaces or dynamically disable the invite‑only feature for sensitive workspaces until a fix is available.
  • Continuously monitor workspace join logs for unauthorized membership attempts and revoke any memberships that result from suspected exploits.

Generated by OpenCVE AI on October 11, 2026 at 13:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Raven 2.0.0 through 3.0.0 contains a missing authorization vulnerability that allows authenticated users to join invite-only Public workspaces by ignoring the can_only_join_via_invite setting. Attackers with the Raven User role can call the join_workspace method to become persistent members, reading and posting in Public and Open channels.
Title Raven 2.0.0 through 3.0.0 Missing Authorization via join_workspace Invite-Only Bypass
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:38.912Z

Reserved: 2026-10-11T01:52:47.396Z

Link: CVE-2026-108731

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:17.207

Modified: 2026-10-11T13:17:17.207

Link: CVE-2026-108731

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:45:03Z

Weaknesses