Vulnerability Description
Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including task inputs, outputs, metadata, and temporal task tokens from other tenants.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/julep-ai/julep/issues/1615
- https://www.vulncheck.com/advisories/julep-insecure-direct-object-reference-via-
- https://github.com/julep-ai/julep/issues/1615
FAQ
What is CVE-2026-67348?
CVE-2026-67348 is a vulnerability with a CVSS score of 8.1 (HIGH). Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply a...
How severe is CVE-2026-67348?
CVE-2026-67348 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-67348?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.