← Volver al buscador de CVEs

CVE-2026-4984

Twilio

Descripción

The Twilio integration webhook handler accepts any POST request without validating Twilio-s -X-Twilio-Signature-. When processing media messages, it fetches user-controlled URLs (-MediaUrlN- parameters) using HTTP requests that include the integration-s Twilio credentials in the -Authorization- header. An attacker can forge a webhook payload pointing to their own server and receive the victim-s -accountSID- and -authToken- in plaintext (base64-encoded Basic Auth), leading to full compromise of the Twilio account.

CVSS 8.2EPSS 0.156%Riesgo 0.83
Ver fuente
Publicación
2026-03-27 15:17:03
Versiones afectadas
unknown
Tipo
Core software
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N