{"id":"CVE-2023-32682","aliases":["GHSA-26c5-ppr8-f33p","PYSEC-2023-84"],"title":"Synapse has improper checks for deactivated users during login","summary":"Synapse has improper checks for deactivated users during login","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","vendor":"matrix-synapse","product":"matrix-synapse","ecosystem":"pip","affected":["matrix-synapse < 1.85.0"],"patched":["matrix-synapse 1.85.0"],"published":"2023-06-06","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:02.042486864Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-26c5-ppr8-f33p","references":[{"url":"https://github.com/matrix-org/synapse/security/advisories/GHSA-26c5-ppr8-f33p"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32682"},{"url":"https://github.com/matrix-org/synapse/issues/12274"},{"url":"https://github.com/matrix-org/synapse/pull/15624"},{"url":"https://github.com/matrix-org/synapse/pull/15634"},{"url":"https://github.com/matrix-org/synapse"},{"url":"https://github.com/matrix-org/synapse/releases/tag/v1.85.0"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2023-84.yaml"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6DH5A5YEB5LRIPP32OUW25FCGZFCZU2"},{"url":"https://matrix-org.github.io/synapse/latest/admin_api/user_admin_api.html#create-or-modify-account"},{"url":"https://matrix-org.github.io/synapse/latest/jwt.html"},{"url":"https://matrix-org.github.io/synapse/latest/usage/configuration/config_documentation.html#password_config"}],"tags":["osv","pip"],"epss":0.00752,"epssPercentile":0.53547,"ingestedAt":"2026-09-12T03:13:01.633Z","slug":"CVE-2023-32682","body":"## Overview\n\n### Impact\nIt may be possible for a deactivated user to login when using uncommon configurations.\n\nThis only applies if any of the following are true:\n\n* [JSON Web Tokens are enabled for login](https://matrix-org.github.io/synapse/latest/jwt.html) via the `jwt_config.enabled` configuration setting\n* The [local password database is enabled](https://matrix-org.github.io/synapse/latest/usage/configuration/config_documentation.html#password_config) via the `password_config.enabled` and `password_config.localdb_enabled` configuration settings *and* a user's password is [updated via an admin API](https://matrix-org.github.io/synapse/latest/admin_api/user_admin_api.html#create-or-modify-account) after a user is deactivated.\n\n**Note that the local password database is enabled by default**, but it is uncommon to set a user's password after they've been deactivated.\n\nInstallations that are configured to only allow login via Single Sign-On (SSO) via CAS, SAML or OpenID Connect (OIDC); or via an external password provider (e.g. LDAP) are not affected.\n\n### Patches\n\n* If using JSON Web Token logins: #15624\n* For other users: #15634\n\n### Workarounds\n\nIf not using JSON Web Tokens, ensure that deactivated users do not have a password set. This list of users can be queried from PostgreSQL:\n\n```sql\nSELECT name FROM users WHERE password_hash IS NOT NULL AND deactivated = 1;\n```\n\n\n\n## Affected packages\n\n- `matrix-synapse < 1.85.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `matrix-synapse 1.85.0`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}