CVE-2026-85619
nicheCross-workspace authorization bypass in AppFlowy-Cloud 0.9.64
AppFlowy-Cloud 0.9.64 contains an incorrect authorization flaw (CWE-863): its collab-object access checks verify the caller's workspace membership but never confirm that the requested object actually belongs to that workspace. An authenticated, low-privileged user can trigger it over the network by sending a request that references a victim's object or document ID together with the attacker's own workspace ID, bypassing the workspace-scoped access control. Successful requests let the attacker read, modify, or delete documents and database rows that live in other users' workspaces, with high impact on the confidentiality, integrity, and availability of that cross-workspace data. The affected population is operators running AppFlowy-Cloud 0.9.64, particularly multi-workspace or multi-tenant deployments where users share one server. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days.
What to do: Operators running AppFlowy-Cloud 0.9.64 should check the project's releases for a patched version and upgrade as soon as one is available, since the advisory does not name a fixed release. Until patching, limit authenticated access to trusted users and treat cross-workspace documents and database rows as potentially readable, modifiable, or deletable by any authenticated user on the same server; review logs for requests referencing object IDs outside the requester's workspace.
| AppFlowy-Cloud | 0.9.64 (the only version named in the advisory; other versions are not confirmed by this data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete cross-workspace data.
- Weakness
- CWE-863
- Vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.