PT-2026-41127 · Tuist · Tuist

·

CVE-2026-44678

·

Published

2026-05-14

·

Updated

2026-05-15

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Tuist versions prior to 1.180.9
Description The "DELETE /api/projects/{account handle}/{project handle}/previews/{preview id}" endpoint loads a preview by its UUID without verifying that the preview belongs to the project resolved from the URL path. The project-level authorization plug AuthorizationPlug, :preview authorizes the caller against the project encoded in account handle and project handle, which can be controlled by an attacker, allowing the deletion of any preview UUID supplied.
Recommendations Update to a version later than 1.180.8.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44678
GHSA-FQP5-HG46-CP2X

Affected Products

Tuist