Access Control Issue in Tuleap Open Source Suite by Enalean
CVE-2025-59040

4.3MEDIUM

Key Information:

Vendor

Enalean

Status
Vendor
CVE Published:
18 September 2025

What is CVE-2025-59040?

Tuleap, an open-source suite designed for managing software development and collaboration, contains an access control vulnerability that allows unauthorized users to view tracker names that they should not have access to. This flaw stems from the improper verification of permissions for child trackers associated with backlog item representations. It is crucial for users of Tuleap to upgrade to the corrected versions to ensure their data and system remain secure.

Affected Version(s)

tuleap < 16.11.99.1757427600

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59040 : Access Control Issue in Tuleap Open Source Suite by Enalean