ZeroHour

CVE-2026-84485

Unauthenticated Member Directory Disclosure in APITable loadOrSearch Endpoint

CVSS 4.0
8.7 high
EPSS
<1%p28
Published
()
Modified
AI analysis

APITable through 1.13.0-beta.1 leaves its internal organization loadOrSearch endpoint accessible without any authentication (CWE-306). An unauthenticated remote attacker who obtains a space identifier from a shared link or a public template can call the endpoint and enumerate the full member directory of the corresponding workspace. The attacker gains member names, email addresses, and the team/organizational hierarchy, which enables reconnaissance, targeted phishing, and social engineering against the workspace's users. Any APITable deployment at or below version 1.13.0-beta.1 that exposes the endpoint to untrusted networks is affected, particularly instances reachable from the internet where sharing links or public templates are in use. Exploitation has not been publicly documented: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns a low 0.3% probability of exploitation in the next 30 days.

What to do: No fixed version is provided in the available data, so monitor for an upstream release newer than 1.13.0-beta.1 and upgrade when available. As an interim mitigation, restrict unauthenticated access to the organization loadOrSearch endpoint (for example via a reverse proxy or WAF rule requiring authentication for that route) and limit internet exposure of APITable instances. Review shared links and public templates to identify which workspace space identifiers are externally discoverable and assess what member data could already have been enumerated.

Affected
APITableall versions through and including 1.13.0-beta.1
Estimated exposure
unknown, likely in the hundreds to low thousands of internet-exposed self-hosted instances — No install-count or scan data is available; APITable is a self-hosted open-source collaboration platform, so affected systems are limited to deployments where the loadOrSearch endpoint is reachable from untrusted networks, a subset of a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.

Weakness
CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.