Authentication Bypass in APITable's Internal User Controller
CVE-2026-80208

8.8HIGH

Key Information:

Vendor

Apitable

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-80208?

APITable versions up to 1.13.0-beta.1 have a vulnerability in the InternalUserController where certain endpoints are accessible without authentication. The requiredLogin annotation is set to false for getUserHistories and closePausedUserAccount endpoints. Due to this flaw, any unauthenticated user can hit the /api endpoints through the nginx gateway, allowing them to enumerate accounts in the cooling-off period after deletion and maliciously close these accounts. This results in permanent data loss and cancellation of user information, undermining account recovery options.

Affected Version(s)

apitable 0 <= 1.13.0-beta.1

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.