Post cover image

April 22, 2026

Authentication bypass via unauthenticated JWT generation on a telecom provider

How a hardcoded Lambda URL in a JS bundle led to admin token generation with no credentials required — and a full chain to AWS credential…

Amrgomaa

2 min read