CVE-2026-24044General

LOWCVSS 9.2 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network attackers to potentially recreate the same key pair, allowing them to impersonate the victim server. The secret is generated by the secrets initialization hook, in the ESS Community Helm Chart values, if both initSecrets.enabled is not set to false and synapse.signingKey is not defined. Given a server key in Matrix authenticates both requests originating from and events constructed on a given server, this potentially impacts confidentiality, integrity and availability of rooms which have a vulnerable server present as a member. The confidentiality of past conversations in end-to-end encrypted rooms is not impacted. The key generation issue was fixed in matrix-tools 0.5.7, released as part of ESS Community Helm Chart 25.12.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-13)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-12: 1Mentions · 2026-02-13: 2Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-13: 102-1202-13
Signal classification3 categories
General
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-121
General1
2026-02-132
Disclosure1Patch1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-24044 Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart… https://www.cve.org/CVERecord?id=CVE-2026-24044

    Post summary

    The post simply references CVE-2026-24044 and links to the CVE record without providing additional details about the vulnerability, exploitation, or mitigation.

    00010166
    56.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-24044 in element-hq ess-helm (<25.12.1) lets attackers recreate server keys & impersonate Matrix servers. Upgrade ESS Community Helm Chart now! 🔐 https://radar.offseq.com/threat/cve-2026-24044-cwe-336-same-seed-in-pseudo-random--1eb14671 #OffSeq #Matrix #C... https://t.co/M9meidO3Mk

    Post summary

    The tweet highlights a critical flaw (CVE‑2026‑24044) that lets attackers recreate server keys and impersonate Matrix servers, and it urges users to upgrade the ESS Community Helm Chart to mitigate the risk.

    0000042
    268 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24044 Matrix Server Key Generation Vulnerability in Element Server Suite Community Edition https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24044

    Post summary

    The entry identifies CVE-2026-24044 as a key‑generation vulnerability in Matrix Element Server Suite Community Edition, but provides no further technical or mitigation details.

    0000041
    4.0K followersView on X

Explore more