{"id":"CVE-2026-65981","title":"Coturn is a free open source implementation of TURN and STUN Server","summary":"Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the or…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","cwe":["CWE-639"],"published":"2026-07-31","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:55:04.493","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-65981","references":[{"url":"https://github.com/coturn/coturn/commit/37df0513168f830a7c9ce0a411db0300fa182f05","label":"security-advisories@github.com"},{"url":"https://github.com/coturn/coturn/security/advisories/GHSA-69wx-x7x6-pjj8","label":"security-advisories@github.com"},{"url":"https://github.com/coturn/coturn/security/advisories/GHSA-69wx-x7x6-pjj8","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00311,"epssPercentile":0.24239,"ingestedAt":"2026-09-09T21:22:45.520Z","slug":"CVE-2026-65981","body":"## Overview\n\nCoturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quota. In the handle_turn_refresh resume branch, the victim allocation (orig_ss) is located solely by the attacker-controlled mobile id, and credentials are only adopted (via copy_auth_parameters) when the resuming session is unauthenticated. Because the attacker's session already has hmackey_set set to 1 from its own prior authentication (which is never reset for long-term-credential sessions), the credential copy is skipped and check_stun_auth validates the REFRESH against the attacker's own identity rather than the allocation owner's. This issue is fixed in version 4.15.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}