CVE-2026-101050
Received Received - Intake

Heym Telegram Webhook Authentication Bypass

Vulnerability report for CVE-2026-101050, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credential_id is absent or secret_token is empty. Remote unauthenticated attackers can post forged Telegram updates to trigger workflows with the owner's configured credentials and execute actions on attacker-supplied input.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
heym heym to 0.0.53 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101050 affects Heym versions before 0.0.53 due to improper authentication. The application fails to verify the X-Telegram-Bot-Api-Secret-Token header when credential_id is missing or secret_token is empty. This allows remote attackers to forge Telegram updates and trigger workflows using the owner's credentials.

Detection Guidance

Check if Heym versions before 0.0.53 are running by inspecting the application version. Monitor webhook endpoints for missing or empty X-Telegram-Bot-Api-Secret-Token header validation. Review logs for unauthorized Telegram update submissions or unexpected workflow triggers.

Impact Analysis

Attackers could execute unauthorized actions on your system by sending malicious Telegram updates. This may lead to data breaches, workflow manipulation, or unauthorized access to sensitive resources controlled by the application.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Compliance may be compromised if sensitive data is exposed or altered.

Mitigation Strategies

Upgrade Heym to version 0.0.53 or later to patch the vulnerability. Ensure the X-Telegram-Bot-Api-Secret-Token header is properly validated for all Telegram webhook endpoints. Configure credential_id and secret_token to prevent unauthenticated access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101050. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart