Authentication Bypass in Coturn by Affected Vendor
CVE-2026-65981
7.1HIGH
What is CVE-2026-65981?
The Coturn server, which implements TURN and STUN functionalities, has a vulnerability that allows an attacker to exploit the authentication mechanisms related to the 'mobility' feature. In versions before 4.15.0, the server fails to validate the identity of a resumed REFRESH request against the original owner's credentials. As a result, an unauthorized user who acquires a victim's MOBILITY-TICKET can manipulate relayed traffic and drain the victim's resources. This occurs because the system associates the victim's allocation solely through an attacker-controlled mobile ID, bypassing proper authentication checks. The flaw has been rectified in version 4.15.0, emphasizing the need for prompt updates to maintain security.
Affected Version(s)
coturn < 4.15.0
