← Πίσω στην αναζήτηση CVE

CVE-2026-4984

Twilio

Περιγραφή

The Twilio integration webhook handler accepts any POST request without validating Twilio-s -X-Twilio-Signature-. When processing media messages, it fetches user-controlled URLs (-MediaUrlN- parameters) using HTTP requests that include the integration-s Twilio credentials in the -Authorization- header. An attacker can forge a webhook payload pointing to their own server and receive the victim-s -accountSID- and -authToken- in plaintext (base64-encoded Basic Auth), leading to full compromise of the Twilio account.

CVSS 8.2EPSS 0.156%Κίνδυνος 0.83
Προβολή πηγής
Δημοσίευση
2026-03-27 15:17:03
Επηρεαζόμενες εκδόσεις
unknown
Τύπος
Core software
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N