PT-2026-97048 · Unleash · Unleash
CVE-2026-76910
·
Published
2026-09-22
·
Updated
2026-09-23
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Unleash versions prior to 8.0.3
Description
An issue exists where the system authorizes the creation of a feature in a destination project but fails to verify if the user has access to the source project. Since feature names are globally unique, a user with create or clone permissions in one project can copy a feature from another project by knowing or guessing its name. This allows the user to inspect the copied feature's strategy parameters, constraints, variants, and variant payloads. The flaw is located in the
cloneFeatureToggle function within src/lib/features/feature-toggle/feature-toggle-service.ts and affects the POST /api/admin/projects/:projectId/features/:featureName/clone endpoint.Recommendations
Update to version 8.0.3.
As a temporary workaround, restrict access to the
POST /api/admin/projects/:projectId/features/:featureName/clone endpoint to minimize the risk of unauthorized configuration disclosure.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unleash