← Terug naar overzicht

AppFlowy-Cloud version 0.9.64 contains a critical authorization vulnerability where the application fails to verify that requested collaboration objects belong to the requesting user's workspace. This flaw allows authenticated attackers to supply a victim's object ID paired with their own workspace ID to bypass access controls entirely. As a result, attackers can read, modify, or delete documents and database rows belonging to other workspaces without proper authorization. The vulnerability exists in the Casbin-based access control logic within the collab authorization module. Exploitation does not require elevated privileges beyond having a valid account, making it accessible to any registered user. The issue was tracked and reported via GitHub issues and further documented by VulnCheck. Affected organizations running self-hosted AppFlowy-Cloud instances should upgrade immediately to a patched version.

Affected products

  • AppFlowy-Cloud 0.9.64

Related CVE's

  • CVE-2026-85619

Categories

  • Cloud & Virtualization
  • Enterprise Applications
  • Identity & Access
  • Web Technologies