CVE-2026-85619
HIGH7.5CVSS v3
—CVSS v2
0.54%
EPSS (exploit probability)
CWE-863CWE
Description
AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete cross-workspace data.
CVSS v3 vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected routers (0)
No routers currently mapped to this CVE in our database.