PT-2026-97050 · Unleash · Unleash
CVE-2026-77426
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Unleash versions prior to 8.0.3
Description
The admin API contains five authorization issues. A missing
await keyword in the POST /api/admin/segments/strategies endpoint allows authenticated users to modify segment assignments without the required UPDATE FEATURE STRATEGY permission. Additionally, several endpoints allow cross-project data access or modification: GET /api/admin/projects/:projectId/features/:featureName/environments/:environment/variants allows disclosure of variant configurations, GET .../strategies/:strategyId allows disclosure of strategy configurations, the getEnvironmentInfo() function allows disclosure of environment information, and PUT /:projectId/tags allows the modification of tags across projects. These issues occur because the system fails to properly validate that the requested features or strategies belong to the specified project context.Recommendations
Update to version 8.0.3.
As a temporary workaround, restrict access to the
POST /api/admin/segments/strategies, GET /api/admin/projects/:projectId/features/:featureName/environments/:environment/variants, GET .../strategies/:strategyId, and PUT /:projectId/tags endpoints to only highly trusted administrators.Exploit
Fix
IDOR
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unleash