{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/unleash-server--8.0.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:unleash:unleash:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-77426"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["unleash-server (\u003c 8.0.3)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","authorization-bypass","idor","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Unleash"],"content_html":"\u003cp\u003eUnleash server versions prior to 8.0.3 are vulnerable to several critical and medium-severity authorization flaws within the admin API. The most significant issue, tracked as CVE-2026-77426, involves a failure to use the 'await' keyword when calling an asynchronous permission check in \u003ccode\u003esegment-controller.ts\u003c/code\u003e. Because the call returns a Promise, which is truthy, the authorization logic defaults to granting access regardless of the user's actual permissions. This flaw allows any authenticated user to modify segment assignments on any strategy across all projects.\u003c/p\u003e\n\u003cp\u003eIn addition to the primary authorization bypass, the Unleash admin API contains multiple Insecure Direct Object Reference (IDOR) vulnerabilities. These flaws permit authenticated attackers to bypass project boundaries to read variant configurations, retrieve strategy details, leak environment information, and modify tags. These issues stem from a failure to validate project ownership or cross-reference parameters against authorized project scopes during API requests. Organizations running affected versions are exposed to unauthorized information disclosure and potential configuration tampering.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows any authenticated user to gain elevated privileges, enabling them to modify feature strategy configurations and perform cross-project read/write operations. This leads to unauthorized access to feature variant definitions, internal strategy details, and project tagging structures. These vulnerabilities undermine the security posture of feature management systems, potentially allowing an attacker to manipulate application behavior or exfiltrate sensitive configuration information across an entire organization's feature toggle environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Unleash server to version 8.0.3 or later immediately to resolve CVE-2026-77426 and associated IDOR vulnerabilities.\u003c/li\u003e\n\u003cli\u003eReview audit logs for unauthorized administrative activity, particularly involving the \u003ccode\u003e/api/admin/segments/strategies\u003c/code\u003e endpoint, starting from the time of deployment of the vulnerable version.\u003c/li\u003e\n\u003cli\u003eImplement restrictive network access controls to ensure that only authorized internal systems and personnel can access the Unleash admin API.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T01:55:47Z","date_published":"2026-09-23T01:55:47Z","id":"https://feed.craftedsignal.io/briefs/2026-09-unleash-auth-bypass/","summary":"Multiple authorization vulnerabilities, including a missing 'await' on a permission check, allow authenticated users to perform unauthorized actions and access sensitive configuration data across projects in Unleash server versions prior to 8.0.3.","title":"Authorization Bypass and IDOR Vulnerabilities in Unleash Admin API","url":"https://feed.craftedsignal.io/briefs/2026-09-unleash-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Unleash-Server (\u003c 8.0.3)","version":"https://jsonfeed.org/version/1.1"}