logo

ClickUp Discloses Exposure of Customer Emails and API Token

ID: b276d969-5780-50c4-b75e-75a52f2b9775

STIX ID: report--b276d969-5780-50c4-b75e-75a52f2b9775

Feed Name: securityonline.info

Threat Score
50/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Ddos

...
...

ClickUp disclosed that a configuration oversight in client-side feature flag targeting (Split.io) exposed 893 customer email addresses and a single active workspace API token between October 7, 2025 and April 27, 2026; the company removed the emails, invalidated the token, and plans automated scanning to prevent PII/credential exposures. The issue was reported earlier but mishandled via triage and spam-filtering delays, and no confirmed malicious access was reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.