Vulnerabilities & Exploits · Web App Attack

OpenCode Messaging Flaw Lets Users Access Other Tenants' SMS

An authenticated low‑privilege user can access SMS messages outside their authorized tenant in OpenCode OC Messaging and USSD Gateway 6.32.2. CISA cataloged the issue as CVE‑2025‑70614.

1 source · Mar 26

CVE-2025-70614

NVD KEV

CVSS 8.1 HIGH: openCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the… EPSS 0.3% (17th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-03-27

Every edition of this story: OpenCode Messaging Flaw Lets Users Access Other Tenants' SMS

More from today