Incorrect authorization in Tolgee - #VU133250
Published: June 2, 2026
Tolgee
Detailed vulnerability description
The vulnerability allows a remote user to read batch job metadata or cancel another project's batch jobs.
The vulnerability exists due to incorrect authorization in the batch job read and cancel endpoints when loading a job by global identifier and checking permissions against the URL project instead of the job's actual project. A remote user can send a specially crafted request to read batch job metadata or cancel another project's batch jobs.
Exposed metadata includes the author identity.