PatchSiren cyber security CVE debrief
CVE-2026-48007 element-hq CVE debrief
CVE-2026-48007 debrief: Element Call, a native Matrix video conferencing application, had a vulnerability in versions 0.5.17 through 0.19.3. The issue involved reporting analytics data to a PostHog server, potentially including full URLs of visited pages with fragments, such as encryption passwords. This exposure affects standalone Element Call 'SPA' instances. The vulnerability is patched in Element Call 0.19.4. Administrators and users should prioritize updating and consider workarounds to mitigate potential exposure.
- Vendor
- element-hq
- Product
- element-call
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-07
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-07
- Advisory updated
- 2026-09-09
Who should care
Element Call administrators and users should assess exposure and prioritize updating to version 0.19.4 or later. Those hosting Element Call as a standalone application should consider disabling PostHog analytics entirely.
Why it matters
CVE-2026-48007 is a high-severity vulnerability in Element Call, a native Matrix video conferencing application. The issue arises from the application's reporting of analytics data to a PostHog server, which may include full URLs of visited pages with fragments, potentially exposing encryption passwords. This vulnerability affects standalone Element Call 'SPA' instances and has been patched in version 0.19.4. Administrators and users should prioritize updating and consider workarounds to mitigate potential exposure.
- Potential exposure of encryption passwords in analytics data
- Possible compromise of call confidentiality for actors with access to PostHog analytics data and encrypted media streams
- Verification priority for Element Call administrators to ensure update to version 0.19.4 or later
- Need for users to opt out of analytics and create new call links
Technical summary
Element Call versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, potentially including full URLs of visited pages with fragments, such as encryption passwords. The issue arises from the application's configuration and URL parameter handling. This vulnerability is patched in Element Call 0.19.4. Some workarounds are available, including opting out of analytics and creating new links for future calls. Affected deployments should prioritize updates and consider disabling PostHog analytics entirely.
Defensive priority
High priority for Element Call administrators and users
Recommended defensive actions
- Element Call administrators should update to version 0.19.4 or later.
- Users should opt out of analytics in the 'Feedback' tab of Element Call's settings.
- Admins should consider disabling PostHog analytics entirely by removing the 'posthog' key from their deployment's config.json file.
- Users should create new links for future calls to avoid potential exposure.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
Evidence from Element Call's GitHub releases and security advisories indicates that versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, potentially including full URLs of visited pages with fragments, such as encryption passwords.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48007 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48007
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48007 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48007
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/element-hq/element-call/releases/tag/v0.19.4
-
Source reference
Unverified legacy reference
URL: https://github.com/element-hq/element-call/security/advisories/GHSA-6vhh-4xw6-h2h2
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.