11 hours ago
Medium
resolved
resolved
JaaS SIP Gateway Authorization Bypass
Bug reported by OffSeq was disclosed at August 12, 2026, 4:07 pm | Missing Authorization
The JaaS SIP gateway endpoint was validated without verifying the tenant's provisioned entitlements. This allowed tenants to place outbound SIP calls regardless of their subscription level. The issue was promptly addressed by implementing server-side entitlement checks to ensure proper authorization enforcement.