CVE-2026-76910
Unleash: Clone-feature lets a user copy a feature from a project they cannot read
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:projectId/features/:featureName/clone authorize creation in the destination project but do not verify access to the source project. Because feature names are globally unique, a user with create or clone permission in one project who knows or guesses another project's feature name can copy that feature into the authorized project and inspect its strategy parameters, constraints, variants, and variant payloads. This issue is fixed in version 8.0.3.
| CWE | CWE-639 |
| Vendor | unleash |
| Product | unleash |
| Published | Sep 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for unleash unleash
Be the first to know when new unknown vulnerabilities affecting unleash unleash are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unleash / unleash
< 8.0.3