Team Deletion Vulnerability in Midday by Midday.ai
CVE-2026-81035
7.2HIGH
What is CVE-2026-81035?
The vulnerability in Midday allows any team member, regardless of their assigned role, to delete an entire team. The function that handles deletions leverages an inaccurate authorization check, which erroneously authorizes all roles in the team-membership table for any deletion action. This results in an invitee possessing the ability to remove the team, along with all associated records. Consequently, this includes a significant risk when paired with the cleanup jobs that utilize bank-connection tokens, potentially compromising connected provider data.
Affected Version(s)
midday e5f45ed0d49cdb34576373623c4579b72daa74c1
