CVE-2026-84485
Unauthenticated Member Directory Disclosure in APITable loadOrSearch Endpoint
APITable through 1.13.0-beta.1 leaves its internal organization loadOrSearch endpoint accessible without any authentication (CWE-306). An unauthenticated remote attacker who obtains a space identifier from a shared link or a public template can call the endpoint and enumerate the full member directory of the corresponding workspace. The attacker gains member names, email addresses, and the team/organizational hierarchy, which enables reconnaissance, targeted phishing, and social engineering against the workspace's users. Any APITable deployment at or below version 1.13.0-beta.1 that exposes the endpoint to untrusted networks is affected, particularly instances reachable from the internet where sharing links or public templates are in use. Exploitation has not been publicly documented: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns a low 0.3% probability of exploitation in the next 30 days.
What to do: No fixed version is provided in the available data, so monitor for an upstream release newer than 1.13.0-beta.1 and upgrade when available. As an interim mitigation, restrict unauthenticated access to the organization loadOrSearch endpoint (for example via a reverse proxy or WAF rule requiring authentication for that route) and limit internet exposure of APITable instances. Review shared links and public templates to identify which workspace space identifiers are externally discoverable and assess what member data could already have been enumerated.
| APITable | all versions through and including 1.13.0-beta.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.
- Weakness
- CWE-306
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.