PT-2026-97050 · Unleash · Unleash

CVE-2026-77426

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Unleash versions prior to 8.0.3
Description The admin API contains five authorization issues. A missing await keyword in the POST /api/admin/segments/strategies endpoint allows authenticated users to modify segment assignments without the required UPDATE FEATURE STRATEGY permission. Additionally, several endpoints allow cross-project data access or modification: GET /api/admin/projects/:projectId/features/:featureName/environments/:environment/variants allows disclosure of variant configurations, GET .../strategies/:strategyId allows disclosure of strategy configurations, the getEnvironmentInfo() function allows disclosure of environment information, and PUT /:projectId/tags allows the modification of tags across projects. These issues occur because the system fails to properly validate that the requested features or strategies belong to the specified project context.
Recommendations Update to version 8.0.3. As a temporary workaround, restrict access to the POST /api/admin/segments/strategies, GET /api/admin/projects/:projectId/features/:featureName/environments/:environment/variants, GET .../strategies/:strategyId, and PUT /:projectId/tags endpoints to only highly trusted administrators.

Exploit

Fix

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77426
GHSA-72H8-WP98-7HCH

Affected Products

Unleash