{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/julep-ai/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-67348"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["julep"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["julep-ai"],"content_html":"\u003cp\u003eJulep is affected by an insecure direct object reference (IDOR) vulnerability (CVE-2026-67348) located in the 'get_execution_details' endpoint. This flaw allows an authenticated tenant to retrieve unauthorized information by manipulating the 'execution_id' parameter. Successful exploitation grants the attacker access to sensitive data belonging to other tenants, including task inputs, outputs, execution metadata, and temporal task tokens. Given that these tokens can be used for further impersonation or unauthorized actions within the platform, this vulnerability poses a significant risk to multi-tenant cloud environments. The issue was identified and patched in commit '5371a620af2582868eb121e6489a8cc14836fd50'.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Julep platform using legitimate tenant credentials.\u003c/li\u003e\n\u003cli\u003eAttacker observes network traffic while interacting with their own execution tasks.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the 'get_execution_details' API call structure and the associated 'execution_id' parameter.\u003c/li\u003e\n\u003cli\u003eAttacker iterates or guesses 'execution_id' values belonging to other tenants.\u003c/li\u003e\n\u003cli\u003eAttacker sends a crafted HTTP GET request to the 'get_execution_details' endpoint with an unauthorized 'execution_id'.\u003c/li\u003e\n\u003cli\u003eThe server fails to validate whether the requester owns the requested 'execution_id'.\u003c/li\u003e\n\u003cli\u003eThe server returns the sensitive execution records, including task inputs and temporal task tokens, to the unauthorized attacker.\u003c/li\u003e\n\u003cli\u003eAttacker uses the stolen temporal task tokens to perform further actions within the context of the victim tenant.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a direct loss of confidentiality for all tenants sharing the same Julep instance. By extracting task inputs, outputs, and temporal task tokens, attackers can perform identity impersonation, data exfiltration, and potentially influence task execution logic for other users. This affects organizations relying on Julep for multi-tenant workflow orchestration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Julep to commit '5371a620af2582868eb121e6489a8cc14836fd50' or later to resolve CVE-2026-67348.\u003c/li\u003e\n\u003cli\u003eReview web server logs for high volumes of requests to the 'get_execution_details' endpoint containing varying 'execution_id' values from a single authenticated session.\u003c/li\u003e\n\u003cli\u003eInspect access logs for instances where a single UserID successfully retrieves data for a large number of distinct 'execution_id' records that do not align with their expected project activity.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-30T15:33:43Z","date_published":"2026-07-30T15:33:43Z","id":"https://feed.craftedsignal.io/briefs/2026-07-julep-idor/","summary":"An insecure direct object reference (IDOR) vulnerability in Julep allows authenticated tenants to bypass authorization checks and access the execution data of other tenants via the get_execution_details endpoint.","title":"Insecure Direct Object Reference Vulnerability in Julep","url":"https://feed.craftedsignal.io/briefs/2026-07-julep-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - Julep-Ai","version":"https://jsonfeed.org/version/1.1"}