Threats / Twilio / CVE-2024-39891
CVE-2024-39891
· EUVD no mirror located
· GCVE no mirror located
Verified 2026-06-22
Twilio Authy vulnerability
Twilio Authy API exposes an unauthenticated endpoint that discloses whether phone numbers are registered with the service, enabling account enumeration attacks.
Verdict
Today item — known-exploited.
An unauthenticated API endpoint in Twilio Authy leaks registration status for queried phone numbers. This information disclosure allows attackers to enumerate valid Authy accounts without credentials, facilitating targeted phishing, social engineering, or account takeover campaigns.
01
Is it exploitable?
— the evidence, ranked above the scoreReported exploitation
4 independent public reports of in-the-wild exploitation are cataloged.Distinct reporting sources (vendor, incident response, government); open them for the underlying claims.
Exploited in the wild
Listed in the CISA Known Exploited Vulnerabilities catalog (added 2024-07-23).
Probability (EPSS)
EPSS 0.01477 — modeled likelihood of exploitation activity.EPSS is a daily-changing model output — open the source for today's value.
Severity / affected
Affected: Twilio, Authy. Confirm exact fixed builds in the vendor advisory.
Weakness (CWE)
Mapped to CWE-203 Observable Discrepancy.CWE assignment from the public NVD record; the weakness class drives how the flaw is exploited.
WeaknessCWE-203 · Observable Discrepancy
02
Who’s exploiting it?
— attribution turns risk into urgencyAttribution not established
No confirmed (advisory-backed) threat-actor attribution is established for this record. Absence of a named actor is not absence of compromise — see Coverage & confidence.
03
Why it matters
— the attack path, told twice: adversary, then board1
Front door — unauthenticated access narrative 1
Attacker
I enumerate phone numbers against the Authy API to identify which ones have active accounts registered.
Business
Customer phone number databases become targets for reconnaissance, reducing the cost and precision of social engineering campaigns against your user base.
2
Keys to the kingdom — privilege/identity takeover narrative 2
Attacker
I use the enumeration results to craft targeted phishing campaigns, knowing which recipients actually use Authy for authentication.
Business
Attackers gain higher success rates in credential theft and account compromise attempts, increasing breach risk across your customer ecosystem.
3
Lateral reach — past segmentation narrative 3
Attacker
I correlate enumeration data with public breach databases to identify high-value targets already exposed elsewhere.
Business
Your customers face elevated risk of coordinated multi-vector attacks combining leaked credentials with confirmed Authy registration status.
04
What to do
— defensible action- Remediate per the vendor advisory — confirm the fixed build for your version and verify exposure.1
Say it to the boardA vulnerability with this evidence profile is a defensible budget line, not a backlog ticket — fund the change against the proof above.
05