PT-2026-97049 · Unleash · Unleash
CVE-2026-77425
·
Published
2026-09-22
·
Updated
2026-09-23
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Unleash versions prior to 8.0.3
Description
An authorization bypass exists in the feature management platform where the system fails to verify if strategy IDs provided in a request body belong to the project, feature, and environment specified in the URL. An authenticated user with
UPDATE FEATURE STRATEGY permissions in one project can reorder activation strategies in any other project or environment by using their own authorized project in the URL while placing the target project's strategy IDs in the request body.This issue affects the following endpoint:
- 'POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order'
The vulnerability involves the
unprotectedUpdateStrategiesSortOrder function and the updateSortOrder function, which update the sort order variable by primary key without context validation. Because Unleash evaluates strategies in order, an attacker can change which strategy determines a feature flag's outcome in production. Additionally, these unauthorized changes are attributed to the attacker's project context, meaning they do not appear in the victim project's audit trail.Recommendations
Update to version 8.0.3.
As a temporary mitigation, restrict access to the 'POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order' endpoint to only highly trusted administrators.
Exploit
Fix
Incorrect Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unleash