Unauthorized Access Vulnerability in APITable by APITable Inc.
CVE-2026-84485
8.7HIGH
What is CVE-2026-84485?
APITable versions up to 1.13.0-beta.1 contain a vulnerability that exposes the internal 'loadOrSearch' endpoint without necessary authentication controls. This oversight allows unauthenticated attackers to access sensitive member directory information, including names, email addresses, and organizational hierarchies. By leveraging space identifiers from shared links or public templates, malicious actors can exploit this endpoint to enumerate the full member directory of any workspace, significantly compromising data privacy and security.
Affected Version(s)
apitable 0 <= 1.13.0-beta.1
