Executive brief
Tuleap Enterprise Edition, a platform used for managing software development lifecycles and team collaboration, contains a security flaw that allows unauthorized access to user data. An attacker could exploit this vulnerability to view sensitive information belonging to other users without needing a password or special permissions. This could lead to the exposure of proprietary project data or personal user information, potentially impacting corporate confidentiality and compliance.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639 (Authorization Bypass Through User-Controlled Key), exists in Tuleap Enterprise Edition versions 17.0 through 17.5. The flaw occurs when the application fails to properly validate that a user has permission to access a specific resource identified by a user-provided key or identifier. A remote, unauthenticated attacker can exploit this by manipulating these identifiers in network requests to access data belonging to other users. The vulnerability has a CVSS 3.1 base score of 7.5, reflecting high confidentiality impact with no requirement for authentication or user interaction. Users are advised to consult the vendor's trust center for specific remediation and patching information.
Affected products
- Dassault Systèmes Tuleap Enterprise Edition 17.0 through 17.5
Timeline
- 2026-07-13: advisory: Initial advisory published by Dassault Systèmes and NVD