PT-2026-66861 · Coturn · Coturn

CVE-2026-65981

·

Published

2026-07-31

·

Updated

2026-08-27

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Coturn versions prior to 4.15.0
Description An authorization bypass exists in servers using the --mobility configuration. The system authenticates a resumed REFRESH request using the resuming user's credentials but fails to verify that identity against the original allocation owner. This occurs in the handle turn refresh resume branch, where the victim allocation (orig ss) is located using an attacker-controlled mobile id. Because the attacker's session may already have hmackey set enabled from prior authentication, the copy auth parameters process is skipped, and check stun auth validates the request against the attacker's identity instead of the owner's. An authenticated attacker who obtains a victim MOBILITY-TICKET can use this to receive and inject relayed traffic and consume the victim's quota.
Recommendations Update to version 4.15.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65981
GHSA-69WX-X7X6-PJJ8
OPENSUSE-SU-2026:11617-1

Affected Products

Coturn