PT-2026-97049 · Unleash · Unleash

CVE-2026-77425

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Unleash versions prior to 8.0.3
Description An authorization bypass exists in the feature management platform where the system fails to verify if strategy IDs provided in a request body belong to the project, feature, and environment specified in the URL. An authenticated user with UPDATE FEATURE STRATEGY permissions in one project can reorder activation strategies in any other project or environment by using their own authorized project in the URL while placing the target project's strategy IDs in the request body.
This issue affects the following endpoint:
  • 'POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order'
The vulnerability involves the unprotectedUpdateStrategiesSortOrder function and the updateSortOrder function, which update the sort order variable by primary key without context validation. Because Unleash evaluates strategies in order, an attacker can change which strategy determines a feature flag's outcome in production. Additionally, these unauthorized changes are attributed to the attacker's project context, meaning they do not appear in the victim project's audit trail.
Recommendations Update to version 8.0.3. As a temporary mitigation, restrict access to the 'POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order' endpoint to only highly trusted administrators.

Exploit

Fix

Incorrect Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77425
GHSA-5FFH-6F9Q-5HHR

Affected Products

Unleash