Improper access control in coTURN - CVE-2026-27624

 

Improper access control in coTURN - CVE-2026-27624

Published: April 20, 2026


Vulnerability identifier: #VU126580
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-27624
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: coTURN
Affected software:
coTURN

Detailed vulnerability description

The vulnerability allows a remote attacker to bypass peer IP access control restrictions.

The vulnerability exists due to improper access control in peer address validation in src/client/ns_turn_ioaddr.c when processing CreatePermission or ChannelBind requests with IPv4-mapped IPv6 XOR-PEER-ADDRESS values. A remote attacker can send a specially crafted request using an ::ffff: IPv4-mapped IPv6 peer address to bypass peer IP access control restrictions.

Exploitation may depend on whether the relay socket is wildcard-bound versus bound to a specific IPv6 address, and on operating system behavior.


How to mitigate CVE-2026-27624

Install security update from vendor's website.

Sources