SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65981

HIGH · CVSS 7.1 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

Coturn versions prior to 4.15.0 are vulnerable to an authentication flaw that allows an attacker to exploit the mobility feature, enabling them to hijack a victim's session and inject relayed traffic by using a stolen MOBILITY-TICKET. This could lead to unauthorized access and depletion of the victim's resource quota. Organizations using Coturn for TURN and STUN services should prioritize upgrading to version 4.15.0 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-65981
Severity
HIGH
CVSS
7.1
EPSS
0.25%

Original NVD Description

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quota. In the handle_turn_refresh resume branch, the victim allocation (orig_ss) is located solely by the attacker-controlled mobile id, and credentials are only adopted (via copy_auth_parameters) when the resuming session is unauthenticated. Because the attacker's session already has hmackey_set set to 1 from its own prior authentication (which is never reset for long-term-credential sessions), the credential copy is skipped and check_stun_auth validates the REFRESH against the attacker's own identity rather than the allocation owner's. This issue is fixed in version 4.15.0.