The external cohort search method failed to properly enforce context-based capability checks. A user with permission to manage cohorts in a local context could enumerate or access data from higher-level (system) cohorts, exposing sensitive administrative information. Versions affected: 5.0 to 5.0.2, 4.5 to 4.5.6, 4.4 to 4.4.10, 4.1 to 4.1.20 and earlier unsupported versions Versions fixed: 5.0.3, 4.5.7, 4.4.11 and 4.1.21