What is CVE-2026-65981?
CVE-2026-65981 is a vulnerability in Coturn server where an authenticated attacker can gain access to another user's allocation by exploiting a flaw in REFRESH request authentication without verifying the original allocation owner. It affects versions prior to 4.15.0, and upgrading to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-65981 Coturn server-də zəiflikdir: hücumçu, autentifikasiyadan keçmiş REFRESH sorğusu ilə başqa istifadəçinin resurslarına (allocation) giriş əldə edə bilər. Bu, 4.15.0 versiyasından əvvəlki versiyalara təsir edir. Serverinizi dərhal ən son versiyaya yeniləməyiniz tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What issue does CVE-2026-65981 cause in Coturn server?
CVE-2026-65981 allows an authenticated attacker to gain unauthorized access to another user's allocation by exploiting the REFRESH request authentication without verifying the original allocation owner.
Which versions of Coturn server are affected by CVE-2026-65981 and how to protect against it?
The vulnerability affects all Coturn versions prior to 4.15.0. It is strongly recommended to upgrade to the latest version immediately to protect against it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.