Authentication Bypass in Coturn by Affected Vendor
CVE-2026-65981

7.1HIGH

Key Information:

Vendor

Coturn

Status
Vendor
CVE Published:
31 July 2026

What is CVE-2026-65981?

The Coturn server, which implements TURN and STUN functionalities, has a vulnerability that allows an attacker to exploit the authentication mechanisms related to the 'mobility' feature. In versions before 4.15.0, the server fails to validate the identity of a resumed REFRESH request against the original owner's credentials. As a result, an unauthorized user who acquires a victim's MOBILITY-TICKET can manipulate relayed traffic and drain the victim's resources. This occurs because the system associates the victim's allocation solely through an attacker-controlled mobile ID, bypassing proper authentication checks. The flaw has been rectified in version 4.15.0, emphasizing the need for prompt updates to maintain security.

Affected Version(s)

coturn < 4.15.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.