Description
HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regardless of their own role or membership in that Space. Versions 1.13.0 through 1.18.2 are affected. The vulnerability has been patched in version 1.18.3, and all users are encouraged to upgrade to this version or later immediately. No known workaround is available.
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in HumHub’s Space member management controller allows any authenticated user, regardless of role or membership, to trigger the removal of all members from any space. In affected versions 1.13.0 through 1.18.2, this results in the total loss of access for all space members and can disrupt collaboration, effectively causing a denial of service for the space. The weakness is identified as CWE‑862 (Missing Authorization).

Affected Systems

HumHub, the open‑source enterprise social network, is affected in all releases from version 1.13.0 through 1.18.2 inclusive. Version 1.18.3 and later contain the fix and are therefore safe.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity with moderate impact. The EPSS score of < 1% suggests that, at present, the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only an authenticated session; no additional privileges or remote code execution capabilities are necessary. The attacking user, making the threat only contingent on account compromise or insider misuse.

Generated by OpenCVE AI on July 30, 2026 at 16:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch to upgrade to HumHub 1.18.3 or later immediately.
  • Limit the use of high‑privilege accounts and verify that only authorized users can manage member lists.
  • Monitor audit logs for unexpected bulk member removal actions and investigate any anomalies promptly.

Generated by OpenCVE AI on July 30, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Humhub
Humhub humhub
Vendors & Products Humhub
Humhub humhub

Tue, 21 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regardless of their own role or membership in that Space. Versions 1.13.0 through 1.18.2 are affected. The vulnerability has been patched in version 1.18.3, and all users are encouraged to upgrade to this version or later immediately. No known workaround is available.
Title HumHub Missing Authorization on Remove All Space Members Action
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-21T18:36:42.028Z

Reserved: 2026-05-19T21:10:38.796Z

Link: CVE-2026-47657

cve-icon Vulnrichment

Updated: 2026-07-21T18:36:38.519Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:00:07Z

Weaknesses