Executive brief
This CVE candidate was withdrawn by its CNA after further investigation determined it was not a security issue. The reported endpoint is intentionally public as part of a legitimate mobile SDK onboarding flow where developers generate codes for users to redeem.
Technical details
CVE-2026-78154 was rejected and withdrawn by its CNA. Initial concern was raised about a public endpoint, but investigation revealed the endpoint's public nature is by design. The mobile SDK onboarding path uses a two-step credential model: a developer authenticates to a dashboard endpoint to generate an invitation code, which the user then inputs into the mobile app to redeem SDK-scoped tokens. The invitation code itself serves as the credential protecting this flow, and no security vulnerability exists in this architecture.