HackerOne Disclosed Reports - 2026-08-12

0 Replies, 13 Views

Logo
Medium
resolved

JaaS SIP Gateway Authorization Bypass


Bug reported by OffSeq was disclosed at August 12, 2026, 4:07 pm   |   Missing Authorization

The JaaS SIP gateway endpoint was validated without verifying the tenant's provisioned entitlements. This allowed tenants to place outbound SIP calls regardless of their subscription level. The issue was promptly addressed by implementing server-side entitlement checks to ensure proper authorization enforcement.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)