PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48007 element-hq CVE debrief

CVE-2026-48007 debrief: Element Call, a native Matrix video conferencing application, had a vulnerability in versions 0.5.17 through 0.19.3. The issue involved reporting analytics data to a PostHog server, potentially including full URLs of visited pages with fragments, such as encryption passwords. This exposure affects standalone Element Call 'SPA' instances. The vulnerability is patched in Element Call 0.19.4. Administrators and users should prioritize updating and consider workarounds to mitigate potential exposure.

Vendor
element-hq
Product
element-call
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-09-09
Advisory published
2026-08-07
Advisory updated
2026-09-09

Who should care

Element Call administrators and users should assess exposure and prioritize updating to version 0.19.4 or later. Those hosting Element Call as a standalone application should consider disabling PostHog analytics entirely.

Why it matters

CVE-2026-48007 is a high-severity vulnerability in Element Call, a native Matrix video conferencing application. The issue arises from the application's reporting of analytics data to a PostHog server, which may include full URLs of visited pages with fragments, potentially exposing encryption passwords. This vulnerability affects standalone Element Call 'SPA' instances and has been patched in version 0.19.4. Administrators and users should prioritize updating and consider workarounds to mitigate potential exposure.

  • Potential exposure of encryption passwords in analytics data
  • Possible compromise of call confidentiality for actors with access to PostHog analytics data and encrypted media streams
  • Verification priority for Element Call administrators to ensure update to version 0.19.4 or later
  • Need for users to opt out of analytics and create new call links

Technical summary

Element Call versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, potentially including full URLs of visited pages with fragments, such as encryption passwords. The issue arises from the application's configuration and URL parameter handling. This vulnerability is patched in Element Call 0.19.4. Some workarounds are available, including opting out of analytics and creating new links for future calls. Affected deployments should prioritize updates and consider disabling PostHog analytics entirely.

Defensive priority

High priority for Element Call administrators and users

Recommended defensive actions

  • Element Call administrators should update to version 0.19.4 or later.
  • Users should opt out of analytics in the 'Feedback' tab of Element Call's settings.
  • Admins should consider disabling PostHog analytics entirely by removing the 'posthog' key from their deployment's config.json file.
  • Users should create new links for future calls to avoid potential exposure.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

Evidence from Element Call's GitHub releases and security advisories indicates that versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, potentially including full URLs of visited pages with fragments, such as encryption passwords.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48007 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48007

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48007 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48007

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.