Skip to content
Data Breach

Critical Meta Vulnerability Exposed Customer Support Emails, Chats, and Uploaded Files

A broken access control flaw in Meta’s shared customer support systems exposed sensitive user data, including emails, chat conversations, and uploaded files. Discovered during security testing of Meta Horizon Managed Solutions, the vulnerability revealed a broader authorization weakness across multi...

· Jul 22, 2026 · 3 min read · 👁 0 views

A broken access control flaw in Meta’s shared customer support systems exposed sensitive user data, including emails, chat conversations, and uploaded files.

Discovered during security testing of Meta Horizon Managed Solutions, the vulnerability revealed a broader authorization weakness across multiple support services within Meta’s ecosystem.

What initially seemed to be a limited product-specific flaw quickly escalated into a cross-platform security risk, affecting Meta.com support systems, customer support chats, and internal case management workflows.

At its core, the vulnerability stemmed from inconsistent enforcement of authorization checks in Meta’s backend infrastructure.

Researchers Rony K Roy found that several GraphQL operations returned sensitive support data even when the requesting user lacked the necessary permissions.

This failure allowed unauthorized users to access support cases, internal notes, escalation details, and attachments linked to other users’ support requests.

Meta Vulnerability Exposed

The exposed data included customer support emails exchanged with Meta, chat transcripts with support agents, case metadata, and files uploaded during support interactions.

In many instances, this information contained personally identifiable information, such as names, email addresses, phone numbers, and other contact details voluntarily shared by users during support engagements.

Further analysis by Rony K Roy showed that support case identifiers were assigned sequentially. When combined with the authorization flaw, this enabled attackers to enumerate case IDs and retrieve large volumes of sensitive support records without proper access rights. This significantly increased the potential impact of the vulnerability.

In addition to unauthorized data access, the flaw also allowed certain actions to be carried out without proper permissions. These actions included creating support requests on behalf of other organizations, modifying support case statuses, and adding external users as subscribers to existing cases.

Such capabilities could have allowed attackers to manipulate support workflows or gain visibility into ongoing support interactions.

The affected infrastructure appeared to rely partially on Salesforce-backed systems however, the vulnerability was not directly related to Salesforce itself.

Instead, it stemmed from flaws in how Meta implemented and integrated authorization controls across shared services. The issue aligns with common security classifications, including Broken Access Control (CWE-284), Insecure Direct Object Reference (CWE-639), and Missing Authorization (CWE-862).

According to a Rony K Roy post, the vulnerability was reported in January 2026, upgraded to critical after its broader impact was discovered, and fully remediated by April, with no evidence of active exploitation.

This incident highlights the risks associated with shared backend architectures, where inconsistent authorization logic can affect multiple services.

It also underscores the importance of enforcing strict access controls and validating permissions at every layer of application workflows, especially in systems handling sensitive customer communications.

The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you