Authorization bypass through user-controlled key in Tuleap Enterprise Edition - CVE-2026-14165
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to access data of other users without authorization.
The vulnerability exists due to authorization bypass through a user-controlled key in Tuleap Enterprise Edition when handling a user-controlled key. A remote attacker can submit a user-controlled key associated with another user to access data of other users without authorization.