CVE-2026-67348

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
30/07/2026
Last modified:
30/07/2026

Description

Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including task inputs, outputs, metadata, and temporal task tokens from other tenants.