PT-2026-41127 · Tuist · Tuist

Highpepicrft

·

Published

2026-05-14

·

Updated

2026-05-15

·

CVE-2026-44678

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Tuist versions prior to 1.180.9
Description The "DELETE /api/projects/{account handle}/{project handle}/previews/{preview id}" endpoint loads a preview by its UUID without verifying that the preview belongs to the project resolved from the URL path. The project-level authorization plug AuthorizationPlug, :preview authorizes the caller against the project encoded in account handle and project handle, which can be controlled by an attacker, allowing the deletion of any preview UUID supplied.
Recommendations Update to a version later than 1.180.8.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-44678

Affected Products

Tuist