PT-2026-66861 · Coturn · Coturn

CVE-2026-65981

·

Publicado

2026-07-31

·

Atualizado

2026-07-31

CVSS v3.1

7.1

Alta

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quota. In the handle turn refresh resume branch, the victim allocation (orig ss) is located solely by the attacker-controlled mobile id, and credentials are only adopted (via copy auth parameters) when the resuming session is unauthenticated. Because the attacker's session already has hmackey set set to 1 from its own prior authentication (which is never reset for long-term-credential sessions), the credential copy is skipped and check stun auth validates the REFRESH against the attacker's own identity rather than the allocation owner's. This issue is fixed in version 4.15.0.

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-65981

Produtos afetados

Coturn