CVE-2025-70614
CVSS 8.1 HIGH: openCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the… EPSS 0.3% (17th percentile).
Vulnerabilities · 173 days ago
An authenticated low‑privilege user can access SMS messages outside their authorized tenant in OpenCode OC Messaging and USSD Gateway 6.32.2. CISA cataloged the issue as CVE‑2025‑70614.
CVSS 8.1 HIGH: openCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the… EPSS 0.3% (17th percentile).
1 source covering this story
OpenCode Systems OC Messaging and Custom Messaging Gateway | CISA
OpenCode Systems OC Messaging and Custom Messaging Gateway Summary Successful exploitation of this vulnerability could allow an authenticated low-privileged user to gain access to SMS messages outside of their authorized tenant scope via a crafted company or tenant identifier…
Part of the PlainSec briefing for 2026-03-27