Open-Source Feature Management Platform Vulnerability in Unleash by Unleash
CVE-2026-63004

5.5MEDIUM

Key Information:

Vendor

Unleash

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-63004?

Unleash, an open-source feature management platform, has a vulnerability in its addon and integration subsystem. Authenticated users with specific permissions can manipulate parametric values. This vulnerability allows them to bypass restrictions on loopback and link-local addresses, potentially causing internal servers to send unauthorized requests. The affected versions failed to safeguard sensitive integration details, leading to possible exposure of API keys and custom headers. The issue was resolved in versions 7.5.2, 7.6.5, and 8.0.2.

Affected Version(s)

unleash < 7.5.2 < 7.5.2

unleash >= 7.6.0, < 7.6.5 < 7.6.0, 7.6.5

unleash >= 8.0.0, < 8.0.2 < 8.0.0, 8.0.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.