{"apiVersion":"1.0","identifier":"CVE-2026-77425","description":"Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUpdateStrategiesSortOrder and updateSortOrder without verifying that the IDs belong to the project, feature, and environment authorized by the URL. In a multi-project Pro or Enterprise deployment, an authenticated user with UPDATE_FEATURE_STRATEGY in one project who knows another project-s strategy IDs can reorder those strategies, changing feature evaluation precedence while the operation is attributed to the attacker-s URL context rather than the affected project. The single-project OSS edition lacks the cross-project dimension, although the missing context binding still permits unauthorized reordering across features or environments in the default project. The endpoint changes only sort_order and does not modify strategy parameters, constraints, or segments. This issue is fixed in version 8.0.3.","publishedAt":"2026-09-22T21:17:32","lastModifiedAt":null,"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77425","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","epssProbability":null,"riskScore":null,"affectedProduct":"Unleash","affectedVersions":"<8.0.3","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-77425","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-77425","en":"https://www.redsauce.net/en/cves/CVE-2026-77425","fr":"https://www.redsauce.net/fr/cves/CVE-2026-77425","pt":"https://www.redsauce.net/pt/cves/CVE-2026-77425","de":"https://www.redsauce.net/de/cves/CVE-2026-77425","sk":"https://www.redsauce.net/sk/cves/CVE-2026-77425","el":"https://www.redsauce.net/el/cves/CVE-2026-77425"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-77425"}}