![]() |
|
HackerOne Disclosed Reports - 2026-08-12 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2026-08-12 (/Thread-HackerOne-Disclosed-Reports-2026-08-12) |
HackerOne disclosed reports - 2026-08-12 - hashXploiter - 08-13-2026
Medium
resolved JaaS SIP Gateway Authorization BypassBug reported by OffSeq was disclosed at August 12, 2026, 4:07 pm | Missing Authorization The JaaS SIP gateway endpoint was validated without verifying the tenant's provisioned entitlements. This allowed tenants to place outbound SIP calls regardless of their subscription level. The issue was promptly addressed by implementing server-side entitlement checks to ensure proper authorization enforcement. |