Team Deletion Vulnerability in Midday by Midday.ai
CVE-2026-81035

7.2HIGH

Key Information:

Vendor

Midday-ai

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-81035?

The vulnerability in Midday allows any team member, regardless of their assigned role, to delete an entire team. The function that handles deletions leverages an inaccurate authorization check, which erroneously authorizes all roles in the team-membership table for any deletion action. This results in an invitee possessing the ability to remove the team, along with all associated records. Consequently, this includes a significant risk when paired with the cleanup jobs that utilize bank-connection tokens, potentially compromising connected provider data.

Affected Version(s)

midday e5f45ed0d49cdb34576373623c4579b72daa74c1

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.