A vulnerability categorized as problematic has been discovered in Element HQ Element Call up to 0.5.17/0.19.3. This issue affects some unknown processing of the file config.json of the component Analytics Reporting. Executing a manipulation of the argument initial_person_info/session_entry_url/current_url/posthogApiHost/posthogApiKey can lead to information disclosure.

The identification of this vulnerability is CVE-2026-48007. The attack may be launched remotely. There is no exploit available.

It is advisable to upgrade the affected component.