ZeroHour

CVE-2026-85619

niche

Cross-workspace authorization bypass in AppFlowy-Cloud 0.9.64

CVSS 4.0
7.7 high
EPSS
<1%p44
Published
()
Modified
AI analysis

AppFlowy-Cloud 0.9.64 contains an incorrect authorization flaw (CWE-863): its collab-object access checks verify the caller's workspace membership but never confirm that the requested object actually belongs to that workspace. An authenticated, low-privileged user can trigger it over the network by sending a request that references a victim's object or document ID together with the attacker's own workspace ID, bypassing the workspace-scoped access control. Successful requests let the attacker read, modify, or delete documents and database rows that live in other users' workspaces, with high impact on the confidentiality, integrity, and availability of that cross-workspace data. The affected population is operators running AppFlowy-Cloud 0.9.64, particularly multi-workspace or multi-tenant deployments where users share one server. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days.

What to do: Operators running AppFlowy-Cloud 0.9.64 should check the project's releases for a patched version and upgrade as soon as one is available, since the advisory does not name a fixed release. Until patching, limit authenticated access to trusted users and treat cross-workspace documents and database rows as potentially readable, modifiable, or deletable by any authenticated user on the same server; review logs for requests referencing object IDs outside the requester's workspace.

Affected
AppFlowy-Cloud0.9.64 (the only version named in the advisory; other versions are not confirmed by this data)
Estimated exposure
nichelikely on the order of a few thousand self-hosted instances at most (no published install counts; AppFlowy-Cloud is an optional, self-hosted sync backend with… — AppFlowy-Cloud is a self-hosted backend adopted per-organization rather than a widely deployed appliance or plugin, and no public active-install counts or internet-exposure scan data exist for it, so the estimate is based on the modest…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete cross-workspace data.

Weakness
CWE-863
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.