Executive Summary
In March 2026, a significant security vulnerability (CVE-2025-70614) was identified in OpenCode Systems' OC Messaging and USSD Gateway version 6.32.2. This flaw allowed authenticated users with low privileges to access SMS messages beyond their authorized scope by manipulating company or tenant identifier parameters. The vulnerability posed a substantial risk to data confidentiality across multi-tenant environments. (sentinelone.com)
The incident underscores the critical importance of robust access control mechanisms in multi-tenant systems. Organizations are urged to review and strengthen their access control policies to prevent similar vulnerabilities and protect sensitive information.
Why This Matters Now
The rise in multi-tenant architectures increases the risk of access control vulnerabilities, making it imperative for organizations to implement stringent security measures to safeguard sensitive data.
Attack Path Analysis
An authenticated low-privileged user exploited a broken access control vulnerability in the OC Messaging and USSD Gateway web control panel by manipulating company or tenant identifier parameters, gaining unauthorized access to SMS messages from other tenants. This unauthorized access led to the exfiltration of sensitive SMS data, potentially compromising the confidentiality of communications across multiple organizations.
Kill Chain Progression
Initial Compromise
Description
An authenticated low-privileged user exploited a broken access control vulnerability in the OC Messaging and USSD Gateway web control panel by manipulating company or tenant identifier parameters.
Related CVEs
CVE-2025-70614
CVSS 8.1OpenCode Systems OC Messaging and USSD Gateway 6.32.2 contain a broken access control vulnerability in the web-based control panel, allowing authenticated low-privileged attackers to access arbitrary SMS messages via a crafted company or tenant identifier parameter.
Affected Products:
OpenCode Systems OC Messaging – 6.32.2
OpenCode Systems USSD Gateway – 6.32.2
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploitation for Privilege Escalation
Exploitation for Credential Access
Abuse Elevation Control Mechanism
Exploit Public-Facing Application
Access Token Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Limit access to system components and cardholder data to only those individuals whose job requires such access.
Control ID: 7.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong identity verification and access controls.
Control ID: Pillar 1: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
OC Messaging and USSD Gateway access control vulnerabilities directly impact SMS/messaging infrastructure, enabling cross-tenant data breaches in communication systems.
Financial Services
SMS-based authentication and transaction notifications vulnerable to unauthorized access, compromising banking security and customer financial data through messaging gateway exploitation.
Health Care / Life Sciences
Patient communication systems using SMS gateways face HIPAA compliance violations as authenticated users could access protected health information across tenant boundaries.
Government Administration
Critical infrastructure communications sector vulnerability enables unauthorized access to government SMS communications, potentially compromising sensitive administrative and citizen service messages.
Sources
- OpenCode Systems OC Messaging and USSD Gatewayhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-085-02Verified
- CVE-2025-70614 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-70614Verified
- USSD Center | Opencode Systemshttps://opencode.com/ussd-gatewayVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it embeds security directly into the cloud fabric, potentially limiting unauthorized access and reducing the blast radius of attacks exploiting broken access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit the broken access control vulnerability may have been constrained, reducing the likelihood of unauthorized access through parameter manipulation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges by accessing other tenants' SMS messages could have been limited, reducing unauthorized data access.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement across tenants could have been constrained, reducing unauthorized access to multiple tenants' data.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain unauthorized access through automated scripts could have been limited, reducing prolonged data exfiltration.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data could have been constrained, reducing the risk of data breaches.
The overall impact of the incident could have been reduced, limiting data breaches and associated reputational damage.
Impact at a Glance
Affected Business Functions
- Messaging Services
- Customer Communications
Estimated downtime: 2 days
Estimated loss: $50,000
Unauthorized access to SMS messages across tenants, potentially exposing sensitive customer communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized lateral movement within the application.
- • Enhance East-West Traffic Security to monitor and control internal communications, detecting and preventing unauthorized data access.
- • Deploy Multicloud Visibility & Control solutions to gain comprehensive insights into cross-tenant activities and detect anomalous behaviors.
- • Utilize Threat Detection & Anomaly Response capabilities to identify and respond to unauthorized access attempts in real-time.
- • Apply Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities, such as broken access control issues, within the application.



