---
id: CVE-2023-32682
aliases:
  - GHSA-26c5-ppr8-f33p
  - PYSEC-2023-84
title: Synapse has improper checks for deactivated users during login
summary: Synapse has improper checks for deactivated users during login
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
vendor: matrix-synapse
product: matrix-synapse
ecosystem: pip
affected:
  - matrix-synapse < 1.85.0
patched:
  - matrix-synapse 1.85.0
published: '2023-06-06'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:02.042486864Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-26c5-ppr8-f33p'
references:
  - url: >-
      https://github.com/matrix-org/synapse/security/advisories/GHSA-26c5-ppr8-f33p
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-32682'
  - url: 'https://github.com/matrix-org/synapse/issues/12274'
  - url: 'https://github.com/matrix-org/synapse/pull/15624'
  - url: 'https://github.com/matrix-org/synapse/pull/15634'
  - url: 'https://github.com/matrix-org/synapse'
  - url: 'https://github.com/matrix-org/synapse/releases/tag/v1.85.0'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2023-84.yaml
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6DH5A5YEB5LRIPP32OUW25FCGZFCZU2
  - url: >-
      https://matrix-org.github.io/synapse/latest/admin_api/user_admin_api.html#create-or-modify-account
  - url: 'https://matrix-org.github.io/synapse/latest/jwt.html'
  - url: >-
      https://matrix-org.github.io/synapse/latest/usage/configuration/config_documentation.html#password_config
tags:
  - osv
  - pip
epss: 0.00752
epssPercentile: 0.53583
ingestedAt: '2026-09-12T03:13:01.633Z'
---

## Overview

### Impact
It may be possible for a deactivated user to login when using uncommon configurations.

This only applies if any of the following are true:

* [JSON Web Tokens are enabled for login](https://matrix-org.github.io/synapse/latest/jwt.html) via the `jwt_config.enabled` configuration setting
* The [local password database is enabled](https://matrix-org.github.io/synapse/latest/usage/configuration/config_documentation.html#password_config) via the `password_config.enabled` and `password_config.localdb_enabled` configuration settings *and* a user's password is [updated via an admin API](https://matrix-org.github.io/synapse/latest/admin_api/user_admin_api.html#create-or-modify-account) after a user is deactivated.

**Note that the local password database is enabled by default**, but it is uncommon to set a user's password after they've been deactivated.

Installations that are configured to only allow login via Single Sign-On (SSO) via CAS, SAML or OpenID Connect (OIDC); or via an external password provider (e.g. LDAP) are not affected.

### Patches

* If using JSON Web Token logins: #15624
* For other users: #15634

### Workarounds

If not using JSON Web Tokens, ensure that deactivated users do not have a password set. This list of users can be queried from PostgreSQL:

```sql
SELECT name FROM users WHERE password_hash IS NOT NULL AND deactivated = 1;
```



## Affected packages

- `matrix-synapse < 1.85.0`

## Remediation

Upgrade to a patched release:

- `matrix-synapse 1.85.0`
