Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omitted from the presences array. This is arguably inconsistent with the UI description of Invisible as "You will appear offline."
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 22 Jan 2026 08:15:00 +0000

Type Values Removed Values Added
Description Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omitted from the presences array. This is arguably inconsistent with the UI description of Invisible as "You will appear offline."
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-22T08:26:11.593Z

Reserved: 2026-01-22T08:10:44.192Z

Link: CVE-2026-24332

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-22T08:16:00.857

Modified: 2026-01-22T08:16:00.857

Link: CVE-2026-24332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses