Junglewise Threat Intelligence

CVE-2026-44678: Tuist Server IDOR in preview deletion API

CVE-2026-44678 · Severity: info · CVSS 7.1 · Published 2026-05-14

Executive brief

Tuist is a platform used by Apple developers to manage and share app previews. A security flaw in the preview deletion system allows any registered user to delete app previews belonging to other organizations or users. This could lead to data loss and disruption of development workflows, as deleted previews and their associated build records can only be recovered from backups.

Technical details

An Insecure Direct Object Reference (IDOR) exists in the `DELETE /api/projects/{account_handle}/{project_handle}/previews/{preview_id}` endpoint. The `AuthorizationPlug` validates the requester's permissions against the project specified in the URL path (which the attacker controls), but the backend logic subsequently deletes the preview identified by the `preview_id` UUID without verifying that it actually belongs to that project. Because `AppBuilds.preview_by_id/2` performed a global lookup without scoping to the resolved project, an authenticated attacker can delete any preview by providing its UUID. This affects both Tuist Cloud and self-hosted deployments. The vulnerability was addressed by scoping the database lookup to the project ID resolved from the URL.

Affected products

  • Tuist Tuist Server <= 1.180.8

Timeline

  • 2026-05-04: advisory: GitHub advisory published
  • 2026-05-14: disclosed: CVE published to NVD

References