← Terug naar overzicht

APITable versions through 1.13.0-beta.1 expose an internal organization loadOrSearch endpoint without any authentication requirement. Unauthenticated attackers can exploit this vulnerability to retrieve sensitive information including member names, email addresses, and team hierarchy structures. The attack vector requires only a space identifier, which can be obtained from publicly shared links or public templates. This allows attackers to enumerate the complete member directory of any workspace. The vulnerability resides in the InternalOrganizationController and is related to missing authentication checks in the ResourceInterceptor. The flaw represents a significant information disclosure risk for organizations using APITable. No authentication or special privileges are required to exploit this issue.

Affected products

  • APITable 1.13.0-beta.1

Related CVE's

  • CVE-2026-84485

Categories

  • Data Breach & Exfiltration
  • Enterprise Applications
  • Identity & Access
  • Web Technologies