CVE-2026-84485
APITable through 1.13.0-beta.1 Missing Authentication on the Internal Organization Load or Search Endpoint
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.
| CWE | CWE-306 |
| Vendor | apitable |
| Product | apitable |
| Published | Sep 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for apitable apitable
Be the first to know when new high vulnerabilities affecting apitable apitable are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
apitable / apitable
0 โค 1.13.0-beta.1
References
github.com: https://github.com/apitable/apitable github.com: https://github.com/apitable/apitable/blob/88b24ce9f359cc434778be75d03603182882dc76/backend-server/application/src/main/java/com/apitable/internal/controller/InternalOrganizationController.java#L58 github.com: https://github.com/apitable/apitable/blob/88b24ce9f359cc434778be75d03603182882dc76/backend-server/application/src/main/java/com/apitable/shared/interceptor/ResourceInterceptor.java#L85 github.com: https://github.com/apitable/apitable/blob/88b24ce9f359cc434778be75d03603182882dc76/backend-server/application/src/main/java/com/apitable/shared/context/LoginContext.java vulncheck.com: https://www.vulncheck.com/advisories/apitable-through-1.13.0-beta.1-missing-authentication-on-the-internal-organization-load-or-search-endpoint
Credits
๐ LeoWSY-hashblue