A vulnerability record disclosed October 2 describes a security flaw in Discord’s open-source libdave implementation of the DAVE end-to-end encryption protocol for voice and video. CVE-2026-104480 says versions before 1.2.0 could accept an unrecognized participant in an encrypted media session under a specific signaling-path attack. Discord’s public repository includes a code change that restores stricter validation.

What the vulnerability describes

The CVE record, assigned by Bugcrowd, says libdave versions 1.1.0 through releases before 1.2.0 did not reject an MLS Welcome message containing an unrecognized user in the resulting group roster. An attacker who could control the DAVE signaling path—such as the voice gateway or an equivalent position able to alter or withhold signaling messages—could cause an affected client to accept an unauthorized participant into the encrypted session. The record rates the issue 9.4 (Critical) under CVSS 4.0. Rapid7’s vulnerability database independently describes the affected library and pre-1.2.0 versions.

This is a protocol/library vulnerability, not a report that Discord accounts or ordinary text messages were exposed. The attack description requires control of the signaling path; the CVE does not say that any Discord user could exploit it simply by sending another user a message.

A validation fix is public

Discord’s public libdave change makes the client reject a Welcome state when it contains an unrecognized user ID. The CVE record links this patch and a libdave 1.2.0 release reference. The published record does not map affected library versions to specific Discord desktop or mobile app build numbers, so there is no reliable client-version cutoff to quote here.

What Discord users should do

Install the latest Discord update offered through Discord’s in-app updater or your device’s official app store; ordinary users update Discord itself rather than independently updating its libdave dependency. If you rely on encrypted voice or video for sensitive conversations, avoid unofficial or modified clients.

The public materials reviewed establish the vulnerability and the upstream code fix, but do not confirm exploitation in the wild or identify which shipped client versions contained the vulnerable code. That uncertainty is why the practical advice is to keep the official app current rather than assume a particular account or call was compromised.