top of page
perceptive_background_267k.jpg

Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant'…

Published:

30 July 2026 at 00:00:00

Alert date:

30 July 2026 at 21:06:06

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Data Breach & Exfiltration

Julep, an AI agent platform, contains an insecure direct object reference (IDOR) vulnerability in its get_execution_details endpoint. Authenticated tenants can exploit this flaw by supplying arbitrary execution_id values to access execution data belonging to other tenants. The exposed data includes sensitive task inputs, outputs, metadata, and temporal task tokens. This represents a significant multi-tenant isolation failure allowing cross-tenant data leakage. The vulnerability is tracked as CVE-2026-67348 and has been reported via GitHub issues and documented by VulnCheck. The issue affects the authorization layer of the API, which fails to validate that the requested execution_id belongs to the requesting tenant. Exploitation requires only valid authentication credentials, lowering the barrier for abuse.

Technical details

Mitigation steps:

Affected products:

Julep

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page