Unrated severityNVD Advisory· Published Jul 30, 2026· Updated Jul 31, 2026
Julep Insecure Direct Object Reference via GET /executions/{execution_id}
CVE-2026-67348
Description
Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including task inputs, outputs, metadata, and temporal task tokens from other tenants.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/julep-ai/julep/issues/1615mitretechnical-descriptionexploitissue-tracking
- www.vulncheck.com/advisories/julep-insecure-direct-object-reference-via-get-executions-execution-idmitrethird-party-advisory
News mentions
0No linked articles in our index yet.