CVE-2026-77426
## Summary Multiple authorization vulnerabilities in Unleash admin API, including a critical missing `await` that completely bypasses a permission check. ## Vulnerability 1: Missing `await` on Permission Check (HIGH) **File:** `src/lib/features/segment/segment-controller.ts` (line 345) `POST /api/admin/segments/strategies` has `permission: NONE` at the route level. The handler performs its own check via `this.accessService.hasPermission()`, but **omits the `await` keyword**. Since `hasPermission()` is async (returns `Promise<boolean>`), the variable always receives a truthy Promise object. The `if (!hasFeatureStrategyPermission)` check never triggers. ```typescript // BUG: missing await - hasPermission() returns Promise<boolean> const hasFeatureStrategyPermission = this.accessService.hasPermission( req.user, UPDATE_FEATURE_STRATEGY, projectId, environmentId, ); if (!hasFeatureStrategyPermission) { // Always false - Promise is truthy! res.status(403).send(); return; } ``` **Impact:** Any authenticated user can modify segment assignments on ANY strategy across ALL projects. **Fix:** Add `await`: `const hasFeatureStrategyPermission = await this.accessService.hasPermission(...)` ## Vulnerability 2: Cross-Project Variant Read (MEDIUM) **File:** `src/lib/routes/admin-api/project/variants.ts` (line 213-223) `GET /api/admin/projects/:projectId/features/:featureName/environments/:environment/variants` completely ignores `projectId`. `getVariantsOnEnv()` only uses `featureName` and `environment`. **Impact:** Any authenticated user can read variant configs (names, weights, payloads) from any project. ## Vulnerability 3: Cross-Project Strategy Read (MEDIUM) **File:** `src/lib/features/feature-toggle/feature-toggle-controller.ts` (line 1107-1116) `GET .../strategies/:strategyId` ignores all params except `strategyId`. Any authenticated user can read any strategy's full configuration. ## Vulnerability 4: Cross-Project Environment Info Leak (MEDIUM) **F
Properties
- ghsa_id
- GHSA-72h8-wp98-7hch
- summary
- Unleash: Missing await on permission check + cross-project IDOR in admin API
- severity
- high
- cve_id
- CVE-2026-77426
- signal_observed_at
- 2026-09-23T04:35:57+00:00
- is_ghsa_only
- false
- ghsa_published
- 2026-09-22T20:36:42Z
- source_url
- https://github.com/advisories/GHSA-72h8-wp98-7hch
- ghsa_updated
- 2026-09-22T20:36:48Z
Related Entities (5)
HAS_WEAKNESS (2)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph