Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases
ID: 62258d42-37c4-53a3-bafd-38fbb72740d4
STIX ID: report--62258d42-37c4-53a3-bafd-38fbb72740d4
Feed Name: Cyber Press
A critical broken access control flaw in Meta’s customer support infrastructure (originating in Horizon Managed Solutions and shared backend services) allowed unauthorized access to private support emails, chat transcripts, case metadata, attachments, and the ability to manipulate support cases and subscribers; the issue mapped to multiple authorization-related CWEs, was reported in January 2026, patched by April 2026 with a $78,000 bounty, and the public write-up omits exploit details to avoid reproduction.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
