← Voltar à pesquisa de CVEs

CVE-2026-4984

Twilio

Descrição

The Twilio integration webhook handler accepts any POST request without validating Twilio-s -X-Twilio-Signature-. When processing media messages, it fetches user-controlled URLs (-MediaUrlN- parameters) using HTTP requests that include the integration-s Twilio credentials in the -Authorization- header. An attacker can forge a webhook payload pointing to their own server and receive the victim-s -accountSID- and -authToken- in plaintext (base64-encoded Basic Auth), leading to full compromise of the Twilio account.

CVSS 8.2EPSS 0.156%Risco 0.83
Ver fonte
Publicação
2026-03-27 15:17:03
Versões afetadas
unknown
Tipo
Core software
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N