Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases
ID: cb72cb2d-0b68-5e66-a7a6-52717fafaa3d
STIX ID: report--cb72cb2d-0b68-5e66-a7a6-52717fafaa3d
Feed Name: GBHackers
Meta remediated a critical broken access control vulnerability in its shared support backend that allowed unauthorized access to and manipulation of support case data (emails, chat transcripts, internal notes, attachments, and metadata) across multiple services. The flaw—rooted in missing authorization checks, insecure direct object references, and predictable case IDs—enabled data enumeration and active abuse (creating/modifying tickets), impacted integrated systems including parts backed by Salesforce, was reported January 2026 and fixed by April 2026 with no evidence of in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
