Sceawere

Vulnerability Detail

CVE-2026-101050UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Heym Authentication Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
15h ago
Vendor
heymrun
Product
heym
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credential_id is absent or secret_token is empty. Remote unauthenticated attackers can post forged Telegram updates to trigger workflows with the owner's configured credentials and execute actions on attacker-supplied input.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-27T17:16:56.100Z",
  "pubdate": "2026-09-27T17:16:56.100Z",
  "executiveSummary": "Heym versions prior to 0.0.53 are susceptible to an authentication bypass vulnerability within its Telegram webhook handling logic.\nThe vulnerability originates from a failure to validate the X-Telegram-Bot-Api-Secret-Token header under specific conditions, specifically when the credential_id is absent or the configured secret_token is null or empty.\nThis flaw allows unauthenticated remote attackers to bypass security controls designed to verify the authenticity of incoming Telegram update requests.\nBy submitting forged Telegram updates to the application's webhook endpoint, an attacker can coerce the system into processing malicious payloads.\nThe potential impact includes the unauthorized execution of workflows using the owner’s pre-configured credentials, enabling the attacker to perform arbitrary actions, potentially leading to data exfiltration, unauthorized API interactions, or unauthorized system state changes.\nThis represents a significant security risk, as the integrity of the automated workflow process is compromised without requiring any prior authentication or authorization.",
  "technicalDetails": "The root cause of this vulnerability is an incomplete validation logic in the webhook request processing mechanism of Heym, specifically related to the verification of the X-Telegram-Bot-Api-Secret-Token header.\nThe application relies on this custom header to ensure that incoming HTTP POST requests originate from the legitimate Telegram Bot API service. However, the implementation fails to enforce this check when the credential_id parameter is not present or when the stored secret_token is an empty string.\nUnder these conditions, the application fails to perform the mandatory signature or token verification, effectively defaulting to a fail-open state.\nAn unauthenticated attacker can identify the webhook endpoint and craft a malicious HTTP request that mimics a valid Telegram update structure. Because the application logic skips the secret token verification, the server treats the forged JSON payload as a legitimate event from the Telegram Bot API.\nThe attack flow proceeds as follows: First, the attacker determines the application's publicly exposed webhook URL. Second, the attacker constructs a forged update payload that targets a specific workflow automation configured within the Heym instance. Third, the attacker transmits this crafted payload to the webhook endpoint. If the server is in a vulnerable state (e.g., misconfiguration of the credential_id or an unset token), the application processes the update without validating the source.\nPost-exploitation, the attacker gains the ability to execute workflows with the privileges assigned to the configured credentials. Since these credentials are used by the application to interact with other systems, the attacker can leverage this trust relationship to perform unauthorized operations, such as triggering external API calls, modifying configurations, or interacting with integrated services on behalf of the victim. This vulnerability is remotely exploitable without requiring authentication, exposing the application to any attacker with network connectivity to the endpoint. The impact is critical as it fundamentally subverts the security boundary established between the public internet and the internal automation workflows."
}
CVE-2026-101050: Heym Authentication Bypass Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere