CVE-2026-67348
HIGHJulep Insecure Direct Object Reference via GET /executions/{execution_id}
Title source: cnaDescription
Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including task inputs, outputs, metadata, and temporal task tokens from other tenants.
References (2)
Core 2
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/julep-ai/julep/issues/1615
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/julep-insecure-direct-object-reference-via-get-executions-execution-id
Scores
CVSS v3
8.1
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-639
Status
published
Products (1)
julep-ai/julep
< 5371a620af2582868eb121e6489a8cc14836fd50
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026