# Critical Tenant Isolation Flaw in OpenCode Messaging Gateway Exposes SMS Messages Across Organizations


## The Threat


OpenCode Systems' widely deployed OC Messaging and USSD Gateway—critical infrastructure components used globally by telecommunications providers and communications platforms—contain a serious access control vulnerability that allows authenticated users to access SMS messages belonging to other tenants. The flaw, tracked as CVE-2025-70614, stems from inadequate validation of identifier parameters, enabling a low-privileged user within one organization to craft requests that bypass tenant isolation boundaries and retrieve sensitive SMS communications from arbitrary other organizations.


The vulnerability represents a textbook example of broken access control in multi-tenant architecture. Rather than requiring elevated privileges or complex exploitation techniques, an attacker needs only a valid user account within the system to craft requests with modified company or tenant identifier parameters. By manipulating these identifiers, the attacker gains unauthorized access to message queues, logs, and communications belonging to completely separate organizations—a fundamental breach of the tenant isolation model that underpins SaaS and cloud-based communications platforms.


This is particularly alarming given OpenCode's position in critical infrastructure for communications. The company, headquartered in Bulgaria, serves telecommunications operators, mobile network operators, and messaging platforms worldwide. SMS gateways are foundational to identity verification, two-factor authentication, password resets, and sensitive business communications. When an attacker can exfiltrate SMS messages across organizational boundaries, the implications extend far beyond the messaging platform itself—they threaten the entire ecosystem of applications that depend on SMS as a secure channel.


## Severity and Impact


| Field | Value |

|-------|-------|

| CVE ID | CVE-2025-70614 |

| CVSS v3.1 Score | 8.1 (HIGH) |

| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |

| Attack Vector | Network |

| Attack Complexity | Low |

| Privileges Required | Low (authenticated user) |

| User Interaction | None |

| Scope | Unchanged |

| Confidentiality Impact | High |

| Integrity Impact | High |

| Availability Impact | None |

| CWE | CWE-284 (Improper Access Control) |

| Affected Versions | v6.32.2 |

| Fixed In | v6.33.11 |


The high CVSS score reflects the practical severity of this vulnerability. While it requires authentication, the barrier to exploitation is minimal—any internal user, contractor, or vendor with legitimate system access can perform the attack. The absence of user interaction requirements means attacks can be automated at scale. Most critically, the vulnerability allows complete disclosure of SMS messages (high confidentiality impact) and potentially their modification (high integrity impact), affecting the core security guarantees that organizations depend on SMS for.


## Affected Products


OpenCode Systems OC Messaging and USSD Gateway are affected in the following versions:


  • OC Messaging 6.32.2
  • USSD Gateway 6.32.2

  • Both products in version 6.32.2 contain the identical access control flaw. Organizations running either product on version 6.33.11 or later are not affected.


    ## Attack Scenario


    An authenticated user with even minimal privileges—perhaps a tier-1 support representative, developer, or third-party integrator—can exploit this vulnerability to systematically access SMS messages from competing organizations or other tenants. The attack is straightforward:


    1. Authenticate to the OpenCode messaging platform using legitimate credentials

    2. Modify the company or tenant identifier parameter in API requests

    3. Replace the authorized identifier with a target organization's identifier

    4. Retrieve SMS messages, delivery receipts, or other message metadata for the target tenant


    No additional exploitation techniques are required. The vulnerability lies in the platform's failure to validate that the authenticated user's tenant affiliation matches the requested tenant. This creates opportunities for industrial espionage, SMS interception, credential theft (if SMS OTPs are exfiltrated), and business disruption.


    ## Mitigations and Recommendations


    Immediate Actions:


    Organizations running OpenCode OC Messaging or USSD Gateway should prioritize upgrading to version 6.33.11 immediately. OpenCode identified and remediated this vulnerability rapidly—discovering it on January 5, 2026 and releasing a fix the following day. This quick turnaround indicates the vendor took the issue seriously, but organizations must act to benefit from the fix.


    For Organizations Unable to Upgrade Immediately:


  • Restrict network access to the messaging gateway from authorized networks only; do not expose the platform to untrusted networks
  • Implement and enforce strict role-based access control (RBAC), limiting user permissions to only necessary operations
  • Monitor logs for suspicious identifier parameters or requests from low-privileged accounts accessing data outside their assigned tenants
  • Disable API access for users and integrations that do not require it
  • Review audit logs for signs of exploitation, including access attempts to tenant identifiers outside the user's authorized scope

  • Defense-in-Depth Strategies:


  • Isolate messaging infrastructure behind firewalls and VPNs; avoid direct internet exposure
  • Implement network segmentation to restrict lateral movement from compromised accounts
  • Deploy intrusion detection and monitoring systems to identify anomalous access patterns
  • Conduct a comprehensive audit of all users with access to the messaging platform, removing unnecessary accounts and privileges
  • Require multi-factor authentication for all platform administrative and API access

  • Incident Response Considerations:


    Organizations concerned about potential exploitation should:


  • Query message logs for access patterns from low-privileged accounts
  • Audit user activity across all tenant contexts to identify unauthorized cross-tenant access
  • Review SMS delivery logs for messages accessed by users outside their assigned organization
  • Contact OpenCode directly at https://opencode.com/about/contact-us for detailed forensic guidance specific to your deployment

  • ## References


  • [CISA ICS Advisory ICSA-26-085-02](https://www.cisa.gov/news-events/ics-advisories/icsa-26-085-02)
  • [CVE-2025-70614 Details](https://nvd.nist.gov/vuln/detail/CVE-2025-70614)
  • [OpenCode Systems Contact Information](https://opencode.com/about/contact-us)
  • [CISA ICS Cybersecurity Recommended Practices](https://www.cisa.gov/ics)
  • [CWE-284: Improper Access Control](https://cwe.mitre.org/data/definitions/284.html)
  • [CISA Technical Information Paper: Targeted Cyber Intrusion Detection and Mitigation Strategies (ICS-TIP-12-146-01B)](https://www.cisa.gov/publications/ics-tip-12-146-01b)

  • ---


    Reporter Credit: Vulnerability discovered and reported by Hussein Amer.