VYPR
High severity7.1NVD Advisory· Published Sep 22, 2026· Updated Sep 22, 2026

Unleash: Missing await on permission check + cross-project IDOR in admin API

CVE-2026-77426

Description

Summary

Multiple authorization vulnerabilities in Unleash admin API, including a critical missing await that completely bypasses a permission check.

Vulnerability 1: Missing await on Permission Check (HIGH)

File: src/lib/features/segment/segment-controller.ts (line 345)

POST /api/admin/segments/strategies has permission: NONE at the route level. The handler performs its own check via this.accessService.hasPermission(), but **omits the await keyword**. Since hasPermission() is async (returns Promise), the variable always receives a truthy Promise object. The if (!hasFeatureStrategyPermission) check never triggers.

// BUG: missing await - hasPermission() returns Promise
const hasFeatureStrategyPermission = this.accessService.hasPermission(
    req.user, UPDATE_FEATURE_STRATEGY, projectId, environmentId,
);
if (!hasFeatureStrategyPermission) { // Always false - Promise is truthy!
    res.status(403).send();
    return;
}

Impact: Any authenticated user can modify segment assignments on ANY strategy across ALL projects.

Fix: Add await: const hasFeatureStrategyPermission = await this.accessService.hasPermission(...)

Vulnerability 2: Cross-Project Variant Read (MEDIUM)

File: src/lib/routes/admin-api/project/variants.ts (line 213-223)

GET /api/admin/projects/:projectId/features/:featureName/environments/:environment/variants completely ignores projectId. getVariantsOnEnv() only uses featureName and environment.

Impact: Any authenticated user can read variant configs (names, weights, payloads) from any project.

Vulnerability 3: Cross-Project Strategy Read (MEDIUM)

File: src/lib/features/feature-toggle/feature-toggle-controller.ts (line 1107-1116)

GET .../strategies/:strategyId ignores all params except strategyId. Any authenticated user can read any strategy's full configuration.

Vulnerability 4: Cross-Project Environment Info Leak (MEDIUM)

File: src/lib/features/feature-toggle/feature-toggle-service.ts (line 1611)

getEnvironmentInfo() doesn't validate feature belongs to project. Compare with getFeature() which calls validateFeatureBelongsToProject().

Vulnerability 5: Cross-Project Tag Modification (LOW)

File: src/lib/features/feature-toggle/feature-toggle-controller.ts (line 576-596)

PUT /:projectId/tags accepts features array in body without validating they belong to projectId.

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.