The Vexa platform has vulnerabilities that allow unauthorized access to meeting data through misconfigured webhooks and internal endpoints.
Claims
The Vexa platform has vulnerabilities that allow unauthorized access to meeting data through misconfigured webhooks and internal endpoints.
Parent: CybersecurityEntity: Vexa platformImpact: negativeDate: Apr 20, 2026Target: The security of the Vexa platform
Source posts
๐จ EUVD-2026-23893
๐ Score: 5.8/10 (CVSS v3.1)
๐ฆ Product: vexa
๐ข Vendor: Vexa-ai
๐
Updated: 2026-04-20
๐ Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa webhook feature allows authenticated users to configure an arbitrary URL that receives HTTP POST requests when meetings complete. The appl...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23893
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-23887
๐ Score: 7.5/10 (CVSS v3.1)
๐ฆ Product: vexa
๐ข Vendor: Vexa-ai
๐
Updated: 2026-04-20
๐ Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa transcription-collector service exposes an internal endpoint `GET /internal/transcripts/{meeting_id}` that returns transcript data for any...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23887
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 20, 2026
#cybersecurity#infosec#euvd#cve#vulnerability