๐Ÿ” CVE Alert

CVE-2026-76910

UNKNOWN 0.0

Unleash: Clone-feature lets a user copy a feature from a project they cannot read

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:projectId/features/:featureName/clone authorize creation in the destination project but do not verify access to the source project. Because feature names are globally unique, a user with create or clone permission in one project who knows or guesses another project's feature name can copy that feature into the authorized project and inspect its strategy parameters, constraints, variants, and variant payloads. This issue is fixed in version 8.0.3.

CWE CWE-639
Vendor unleash
Product unleash
Published Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for unleash unleash

Be the first to know when new unknown vulnerabilities affecting unleash unleash are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unleash / unleash
< 8.0.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Unleash/unleash/security/advisories/GHSA-8xcj-9hfr-fh9j github.com: https://github.com/Unleash/unleash/commit/2dc6ac0e8ba524ec7a2e9bc96a0e01d9d6f5a35a github.com: https://github.com/Unleash/unleash/releases/tag/v8.0.3