Authentication Bypass Issue in Heym Product by Heymrun
CVE-2026-101050

8.3HIGH

Key Information:

Vendor

Heymrun

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101050?

The Heym product prior to version 0.0.53 has a significant flaw in how it handles the X-Telegram-Bot-Api-Secret-Token header in its webhook endpoints. When the credential_id is missing or the secret_token is left empty, this creates an opportunity for remote unauthenticated attackers to send forged Telegram updates. This vulnerability allows attackers to exploit workflows configured by the owner, potentially leading to unauthorized actions executed using attacker-supplied input. It is crucial for users of the affected versions to apply the necessary updates to ensure the security of their applications.

Affected Version(s)

heym 0 < 0.0.53

heym 0.0.53

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

okcomputerfan
mbakgun
.