Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-84485— APITable through 1.13.0-beta.1 Missing Authentication on the Internal Organization Load or Search Endpoint

Quick assessment

Affected
apitable apitable
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

APITable 1.13.0-beta.1 之前的版本未对内部的组织加载/搜索端点( )进行身份验证,使得未认证的攻击者能够获取成员姓名、电子邮件地址以及团队层级结构。攻击者可以利用从共享链接或公开模板中获取的工作空间标识符查询该端点,从而枚举任意工作空间的完整成员目录。

CVSS 7.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84485

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
APITable through 1.13.0-beta.1 Missing Authentication on the Internal Organization Load or Search Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
apitable apitable 0 ~ 1.13.0-beta.1 -

II. Public POCs for CVE-2026-84485

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84485

登录查看更多情报信息。

Patches & Fixes for CVE-2026-84485 (2)

Vendor Advisories for CVE-2026-84485 (1)

Other References for CVE-2026-84485 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-84485

No comments yet


Leave a comment