CVE-2025-70614
CVSS 8.1 HIGH: openCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the… EPSS 0.3% (17th percentile).
Vulnerabilities & Exploits · Web App Attack
An authenticated low‑privilege user can access SMS messages outside their authorized tenant in OpenCode OC Messaging and USSD Gateway 6.32.2. CISA cataloged the issue as CVE‑2025‑70614.
1 source · Mar 26
CVSS 8.1 HIGH: openCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the… EPSS 0.3% (17th percentile).
CISA Advisories
OpenCode Systems OC Messaging and Custom Messaging Gateway | CISA
OpenCode Systems OC Messaging and Custom Messaging Gateway Summary Successful exploitation of this vulnerability could allow an authenticated low-privileged user to gain access to SMS messages outside of their authorized tenant scope via a crafted company or tenant identifier…
originalPart of the PlainSec briefing for 2026-03-27
Every edition of this story: OpenCode Messaging Flaw Lets Users Access Other Tenants' SMS