An authenticated low‑privilege user can access SMS messages outside their authorized tenant in OpenCode OC Messaging and USSD Gateway 6.32.2. CISA cataloged the issue as CVE‑2025‑70614.
Part of the PlainSec briefing for 2026-03-27