Meta remediated a critical authorization flaw in its customer support infrastructure after independent researcher Rony K. Roy found that backend GraphQL operations did not consistently verify support case ownership. The weakness, first identified while testing Meta Horizon Managed Solutions, reportedly extended into broader Meta.com support workflows and created an IDOR-style exposure because support case IDs were sequential and predictable. Sensitive records that could have been accessed included emails, live chats, attachments, internal case metadata, and other personally identifiable information.
Roy said the vulnerability chain also enabled unauthorized actions beyond data access, including creating support requests for other organizations, changing case status, and adding external subscribers to cases. Meta was notified in January 2026 and completed remediation in April, and the company said it found no evidence of malicious exploitation in the wild. Roy reported receiving a $78,000 bug bounty for the discovery, while reporting indicated the issue stemmed from Meta’s authorization logic rather than any underlying Salesforce-backed support components.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Rony K. Roy said he received a $78,000 bug bounty for the Meta support infrastructure vulnerability. One source reports the award directly, while another notes Meta did not publicly confirm the payout.
Meta completed remediation of the reported support infrastructure flaws in April 2026. The company said it found no evidence that the vulnerability had been exploited in the wild.
Independent researcher Rony K. Roy reported a chain of authorization weaknesses in Meta's customer support infrastructure in January 2026. The issues could have exposed support records and enabled unauthorized actions such as creating or modifying support cases for other organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.