


Perceptive Security
SOC/SIEM Consultancy

Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant'…
Published:
30 juli 2026 om 00:00:00
Alert date:
30 juli 2026 om 21:06:06
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Data Breach & Exfiltration
Julep, an AI agent platform, contains an insecure direct object reference (IDOR) vulnerability in its get_execution_details endpoint. Authenticated tenants can exploit this flaw by supplying arbitrary execution_id values to access execution data belonging to other tenants. The exposed data includes sensitive task inputs, outputs, metadata, and temporal task tokens. This represents a significant multi-tenant isolation failure allowing cross-tenant data leakage. The vulnerability is tracked as CVE-2026-67348 and has been reported via GitHub issues and documented by VulnCheck. The issue affects the authorization layer of the API, which fails to validate that the requested execution_id belongs to the requesting tenant. Exploitation requires only valid authentication credentials, lowering the barrier for abuse.
Technical details
Mitigation steps:
Affected products:
Julep
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67348
https://github.com/julep-ai/julep/issues/1615
https://www.vulncheck.com/advisories/julep-insecure-direct-object-reference-via-get-executions-execution-id
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
