Medium
resolved
resolved
Ability to access policy and updates for unauthorized program
Bug reported by was disclosed at May 8, 2025, 4:11 pm | Improper Access Control - Generic
The vulnerability allowed an unauthorized user to access the policy and updates for a restricted program using an API key. The user was able to retrieve sensitive data from the unauthorized program, even though they were only granted access to one of the two programs in the organization.

