CVE-2026-77425Medium· 4.3▾ SunlitUnleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUp…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUpdateStrategiesSortOrder and updateSortOrder without verifying that the IDs belong to the project, feature, and environment authorized by the URL. In a multi-project Pro or Enterprise deployment, an authenticated user with UPDATE_FEATURE_STRATEGY in one project who knows another project's strategy IDs can reorder those strategies, changing feature evaluation precedence while the operation is attributed to the attacker's URL context rather than the affected project. The single-project OSS edition lacks the cross-project dimension, although the missing context binding still permits unauthorized reordering across features or environments in the default project. The endpoint changes only sort_order and does not modify strategy parameters, constraints, or segments. This issue is fixed in version 8.0.3.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
unleash-server < 8.0.3Patched in:
unleash-server 8.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-76910Medium· 5.3Unleash is an open-source feature management platform
CVE-2026-77426High· 7.1Unleash is an open-source feature management platform
CVE-2026-76909Low· 2.1Unleash is an open-source feature management platform
CVE-2026-63466Medium· 4.1Unleash is an open-source feature management platform
CVE-2026-63462High· 7.5Unleash is an open-source feature management platform
CVE-2026-63004Medium· 5.5Unleash is an open-source feature management platform