Dark C0d3rs

Full Version: HackerOne Disclosed Reports - 2026-08-12
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Logo
Medium
resolved

JaaS SIP Gateway Authorization Bypass


Bug reported by OffSeq was disclosed at August 12, 2026, 4:07 pm   |   Missing Authorization

The JaaS SIP gateway endpoint was validated without verifying the tenant's provisioned entitlements. This allowed tenants to place outbound SIP calls regardless of their subscription level. The issue was promptly addressed by implementing server-side entitlement checks to ensure proper authorization enforcement.