Katello's ContentUploadsController does not enforce product-scoped authorization on repository_id. A user with edit_products limited to specific products can call /katello/api/v2/repositories/:id/content_uploads against repositories outside that scope. Impact is information disclosure only.