CVE-2026-24044 Details
Description
Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network attackers to potentially recreate the same key pair, allowing them to impersonate the victim server. The secret is generated by the secrets initialization hook, in the ESS Community Helm Chart values, if both initSecrets.enabled is not set to false and synapse.signingKey is not defined. Given a server key in Matrix authenticates both requests originating from and events constructed on a given server, this potentially impacts confidentiality, integrity and availability of rooms which have a vulnerable server present as a member. The confidentiality of past conversations in end-to-end encrypted rooms is not impacted. The key generation issue was fixed in matrix-tools 0.5.7, released as part of ESS Community Helm Chart 25.12.1.
A vulnerability exists in Element Server Suite Community Edition (ESS Community) prior to version 25.12.2, within the Helm Chart's secrets initialization hook. This hook, when using the matrix-tools container version prior to 0.5.7, employs an insecure method for generating Matrix server keys. As a result, network attackers could potentially recreate the same key pair and impersonate the victim server. The vulnerability arises if 'initSecrets.enabled' is not set to false and 'synapse.signingKey' is not defined. The flawed key generation method could disrupt the functionality of rooms where the compromised server is a member, although it does not affect the confidentiality of past conversations in end-to-end encrypted rooms.
Upgrade to Element Server Suite Community Edition version 25.12.2, which includes the patched key generation method and automatically revokes the old signing key. For those who cannot upgrade immediately, a manual fix is available by following the instructions in the Element ESS Helm repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 12, 2026CISA-ADP
Assessed Feb 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-336 | Same Seed in Pseudo-Random Number Generator (PRNG) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Element Server Suite Community | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 12, 2026 | New CVE Received | [email protected] |
Volerion