PT-2026-66861 · Coturn · Coturn
CVE-2026-65981
·
Published
2026-07-31
·
Updated
2026-08-27
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Coturn versions prior to 4.15.0
Description
An authorization bypass exists in servers using the
--mobility configuration. The system authenticates a resumed REFRESH request using the resuming user's credentials but fails to verify that identity against the original allocation owner. This occurs in the handle turn refresh resume branch, where the victim allocation (orig ss) is located using an attacker-controlled mobile id. Because the attacker's session may already have hmackey set enabled from prior authentication, the copy auth parameters process is skipped, and check stun auth validates the request against the attacker's identity instead of the owner's. An authenticated attacker who obtains a victim MOBILITY-TICKET can use this to receive and inject relayed traffic and consume the victim's quota.Recommendations
Update to version 4.15.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coturn