CVE-2026-77425

MEDIUM

Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-...

CVSS 3.14.3
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, no availability impact.
CWE Weakness Definitions
CWE-639: Authorization Bypass Through User-Controlled Key (IDOR)

Software uses a user-supplied key to access resources without verifying authorization for that specific resource.

CWE-863: Incorrect Authorization

Software performs an authorization check incorrectly, allowing access beyond intended privileges.

◆ SAGE Intelligence — CITED Relevance Research Team

A medium severity vulnerability (CVE-2026-77425) affects the target system. Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUpdateStrategie...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-77425?
A medium severity vulnerability (CVE-2026-77425) affects the target system. Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUpdateStrategie...
What is the CVSS score for CVE-2026-77425?
CVE-2026-77425 has CVSS 4.3 (Medium). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N.
Is CVE-2026-77425 actively exploited?
No confirmed active exploitation of CVE-2026-77425 as of 2026-09-23.
How do I remediate CVE-2026-77425?
Apply vendor patches for CVE-2026-77425. Monitor the vendor advisories.
Vulnerability Details
CVE IDCVE-2026-77425
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Published2026-09-22
Last Modified2026-09-22
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUpdateStrategiesSortOrder and updateSortOrder without verifying that the IDs belong to the project, feature, and environment authorized by the URL. In a multi-project Pro or Enterprise deployment, an authenticated user with UPDATE_FEATURE_STRATEGY in one project who knows another project's strategy IDs can reorder those strategies, changing feature evaluation precedence while the operation is attributed to the attacker's URL context rather than the affected project. The single-project OSS edition lacks the cross-project dimension, although the missing context binding still permits unauthorized reordering across features or environments in the default project. The endpoint changes only sort_order and does not modify strategy parameters, constraints, or segments. This issue is fixed in version 8.0.3.

Source: NIST NVD / MITRE CVE Database

Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 0 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →