SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-67348

HIGH · CVSS 8.1 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The vulnerability in Julep's get_execution_details endpoint allows authenticated users to exploit insecure direct object references, enabling them to access sensitive execution data from other tenants by manipulating execution_id values. This could lead to unauthorized disclosure of task inputs, outputs, and metadata, posing a significant risk to tenant data privacy. Organizations using Julep should prioritize addressing this issue to safeguard against potential data breaches and ensure tenant isolation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67348
Severity
HIGH
CVSS
8.1
EPSS
0.25%

Original NVD Description

Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including task inputs, outputs, metadata, and temporal task tokens from other tenants.