logo

Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases

ID: 62258d42-37c4-53a3-bafd-38fbb72740d4

STIX ID: report--62258d42-37c4-53a3-bafd-38fbb72740d4

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Tamilselvan

...
...

A critical broken access control flaw in Meta’s customer support infrastructure (originating in Horizon Managed Solutions and shared backend services) allowed unauthorized access to private support emails, chat transcripts, case metadata, attachments, and the ability to manipulate support cases and subscribers; the issue mapped to multiple authorization-related CWEs, was reported in January 2026, patched by April 2026 with a $78,000 bounty, and the public write-up omits exploit details to avoid reproduction.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.