Authorization bypass through user-controlled key in Tolgee - #VU133247
Published: June 2, 2026
Tolgee
Detailed vulnerability description
The vulnerability allows a remote user to modify another project's content storage configuration or disclose sensitive information.
The vulnerability exists due to authorization bypass through user-controlled key in the content storage update and test endpoints when handling requests with a foreign content storage identifier under an authorized project URL. A remote user can send a specially crafted request to modify another project's content storage configuration or disclose sensitive information.
Testing a foreign storage configuration may expose existing storage secrets.