Improper Enforcement of Message Integrity During Transmission in a Communication Channel in coTURN - CVE-2026-68554

 

Improper Enforcement of Message Integrity During Transmission in a Communication Channel in coTURN - CVE-2026-68554

Published: August 3, 2026


Vulnerability identifier: #VU140775
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68554
CWE-ID: CWE-924
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify authenticated TURN requests.

The vulnerability exists due to improper enforcement of message integrity during transmission in TURN request attribute parsing when processing STUN attributes that appear after MESSAGE-INTEGRITY. A remote attacker can append crafted attributes to an authenticated request and adjust the STUN header length to modify authenticated TURN requests.

Exploitation requires an on-path position and affects plain UDP and TCP listeners; TLS and DTLS deployments are not affected.


Affected software

coTURN

How to mitigate CVE-2026-68554

Install security update from vendor's website.

coTURN - update to 4.15.0

External References

Related Security Bulletins