CVE Explorer
CVE-2026-24044
Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network attackers to potentially recreate the same key pair, allowing them to impersonate the victim server. The secret is generated by the secrets initialization hook, in the ESS Community Helm
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"product":"ess-helm","vendor":"element-hq","versions":[{"status":"affected","version":"< 25.12.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9165f5680096117cabdc4ab34f7aa55a5655bf5e62daefb2e4929840fde3b570 · sha256:5822c6d725a2590e… · /containers/cna/affected/0
{"product":"matrix-tools","vendor":"element-hq","versions":[{"status":"affected","version":"< 0.5.7"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9165f5680096117cabdc4ab34f7aa55a5655bf5e62daefb2e4929840fde3b570 · sha256:5822c6d725a2590e… · /containers/cna/affected/1
Affected products and versions
2 source assertions{"product":"ess-helm","vendor":"element-hq","versions":[{"status":"affected","version":"< 25.12.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9165f5680096117cabdc4ab34f7aa55a5655bf5e62daefb2e4929840fde3b570 · sha256:5822c6d725a2590e… · /containers/cna/affected/0
{"product":"matrix-tools","vendor":"element-hq","versions":[{"status":"affected","version":"< 0.5.7"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9165f5680096117cabdc4ab34f7aa55a5655bf5e62daefb2e4929840fde3b570 · sha256:5822c6d725a2590e… · /containers/cna/affected/1
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.2,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9165f5680096117cabdc4ab34f7aa55a5655bf5e62daefb2e4929840fde3b570 · sha256:5822c6d725a2590e… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-336","description":"CWE-336: Same Seed in Pseudo-Random Number Generator (PRNG)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9165f5680096117cabdc4ab34f7aa55a5655bf5e62daefb2e4929840fde3b570 · sha256:5822c6d725a2590e… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/element-hq/ess-helm/blob/main/docs/maintenance.md#fixing-cve-2026-24044elementsec-2025-1670-manually","tags":["x_refsource_MISC"],"url":"https://github.com/element-hq/ess-helm/blob/main/docs/maintenance.md#fixing-cve-2026-24044elementsec-2025-1670-manually"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9165f5680096117cabdc4ab34f7aa55a5655bf5e62daefb2e4929840fde3b570 · sha256:5822c6d725a2590e… · /containers/cna/references/1
{"name":"https://github.com/element-hq/ess-helm/releases/tag/25.12.2","tags":["x_refsource_MISC"],"url":"https://github.com/element-hq/ess-helm/releases/tag/25.12.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9165f5680096117cabdc4ab34f7aa55a5655bf5e62daefb2e4929840fde3b570 · sha256:5822c6d725a2590e… · /containers/cna/references/2
{"name":"https://github.com/element-hq/ess-helm/security/advisories/GHSA-qwcj-h6m8-vp6q","tags":["x_refsource_CONFIRM"],"url":"https://github.com/element-hq/ess-helm/security/advisories/GHSA-qwcj-h6m8-vp6q"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9165f5680096117cabdc4ab34f7aa55a5655bf5e62daefb2e4929840fde3b570 · sha256:5822c6d725a2590e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.