Description
An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization.
Published: 2026-07-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization bypass through a user‑controlled key allows an attacker to retrieve information belonging to other users in Tuleap Enterprise Edition without proper authorization. The vulnerability is a flaw in the handling of user‑supplied keys, resulting in a confidentiality compromise. An exploited instance would enable an attacker to read, modify, or delete project data and personal user information normally protected by access controls.

Affected Systems

The affected systems are Dassault Systèmes Tuleap Enterprise Edition versions 17.0 through 17.5.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, and the EPSS score of < 1 % indicates a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. It is inferred that the attack vector requires an authenticated user who has permission to create or modify keys; the attacker would supply a crafted key that bypasses authorization checks and grants access to another user’s data. Once the bypass is achieved, the attacker can exfiltrate confidential information from the vulnerable instance.

Generated by OpenCVE AI on August 1, 2026 at 10:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Tuleap Enterprise Edition to version 17.6 or later when the vendor releases the official fix.
  • If a patch is not yet available, restrict or remove the permissions that allow users to create or modify keys in the configuration, limiting the attack surface.
  • Continuously monitor audit logs for abnormal data access patterns to detect potential exploitation early.

Generated by OpenCVE AI on August 1, 2026 at 10:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Dassault Systèmes
Dassault Systèmes tuleap Enterprise Edition
Vendors & Products Dassault Systèmes
Dassault Systèmes tuleap Enterprise Edition

Mon, 13 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization.
Title Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dassault Systèmes Tuleap Enterprise Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: 3DS

Published:

Updated: 2026-07-13T14:47:37.703Z

Reserved: 2026-06-30T06:02:28.161Z

Link: CVE-2026-14165

cve-icon Vulnrichment

Updated: 2026-07-13T14:47:34.431Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:00:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key