# Critical Tenant Isolation Flaw in OpenCode Messaging Gateway Exposes SMS Messages Across Organizations
## The Threat
OpenCode Systems' widely deployed OC Messaging and USSD Gateway—critical infrastructure components used globally by telecommunications providers and communications platforms—contain a serious access control vulnerability that allows authenticated users to access SMS messages belonging to other tenants. The flaw, tracked as CVE-2025-70614, stems from inadequate validation of identifier parameters, enabling a low-privileged user within one organization to craft requests that bypass tenant isolation boundaries and retrieve sensitive SMS communications from arbitrary other organizations.
The vulnerability represents a textbook example of broken access control in multi-tenant architecture. Rather than requiring elevated privileges or complex exploitation techniques, an attacker needs only a valid user account within the system to craft requests with modified company or tenant identifier parameters. By manipulating these identifiers, the attacker gains unauthorized access to message queues, logs, and communications belonging to completely separate organizations—a fundamental breach of the tenant isolation model that underpins SaaS and cloud-based communications platforms.
This is particularly alarming given OpenCode's position in critical infrastructure for communications. The company, headquartered in Bulgaria, serves telecommunications operators, mobile network operators, and messaging platforms worldwide. SMS gateways are foundational to identity verification, two-factor authentication, password resets, and sensitive business communications. When an attacker can exfiltrate SMS messages across organizational boundaries, the implications extend far beyond the messaging platform itself—they threaten the entire ecosystem of applications that depend on SMS as a secure channel.
## Severity and Impact
| Field | Value |
|-------|-------|
| CVE ID | CVE-2025-70614 |
| CVSS v3.1 Score | 8.1 (HIGH) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | Low (authenticated user) |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | None |
| CWE | CWE-284 (Improper Access Control) |
| Affected Versions | v6.32.2 |
| Fixed In | v6.33.11 |
The high CVSS score reflects the practical severity of this vulnerability. While it requires authentication, the barrier to exploitation is minimal—any internal user, contractor, or vendor with legitimate system access can perform the attack. The absence of user interaction requirements means attacks can be automated at scale. Most critically, the vulnerability allows complete disclosure of SMS messages (high confidentiality impact) and potentially their modification (high integrity impact), affecting the core security guarantees that organizations depend on SMS for.
## Affected Products
OpenCode Systems OC Messaging and USSD Gateway are affected in the following versions:
Both products in version 6.32.2 contain the identical access control flaw. Organizations running either product on version 6.33.11 or later are not affected.
## Attack Scenario
An authenticated user with even minimal privileges—perhaps a tier-1 support representative, developer, or third-party integrator—can exploit this vulnerability to systematically access SMS messages from competing organizations or other tenants. The attack is straightforward:
1. Authenticate to the OpenCode messaging platform using legitimate credentials
2. Modify the company or tenant identifier parameter in API requests
3. Replace the authorized identifier with a target organization's identifier
4. Retrieve SMS messages, delivery receipts, or other message metadata for the target tenant
No additional exploitation techniques are required. The vulnerability lies in the platform's failure to validate that the authenticated user's tenant affiliation matches the requested tenant. This creates opportunities for industrial espionage, SMS interception, credential theft (if SMS OTPs are exfiltrated), and business disruption.
## Mitigations and Recommendations
Immediate Actions:
Organizations running OpenCode OC Messaging or USSD Gateway should prioritize upgrading to version 6.33.11 immediately. OpenCode identified and remediated this vulnerability rapidly—discovering it on January 5, 2026 and releasing a fix the following day. This quick turnaround indicates the vendor took the issue seriously, but organizations must act to benefit from the fix.
For Organizations Unable to Upgrade Immediately:
Defense-in-Depth Strategies:
Incident Response Considerations:
Organizations concerned about potential exploitation should:
## References
---
Reporter Credit: Vulnerability discovered and reported by Hussein Amer.