ClickUp Discloses Feature Flag Misconfiguration That Exposed 893 Customer Email Addresses and a Live API Token
ID: 9b4a0d94-ebd5-5231-9b2f-6de629113baf
STIX ID: report--9b4a0d94-ebd5-5231-9b2f-6de629113baf
Feed Name: The Cyber Express
Threat Score
**Executive summary:** ClickUp exposed 893 customer email addresses and one live customer API token by embedding them in Split.io feature-flag targeting rules that are retrievable via the public client-side SDK key; the issue was discovered publicly on April 27, 2026 and ClickUp removed the PII, invalidated the token, notified affected customers, and implemented automated detection and secrets scanning for flag configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
