Field-Level Permission Exposure in Twenty CRM
CVE-2026-85055

7.1HIGH

Key Information:

Vendor

Twentyhq

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-85055?

Twenty is an open-source CRM platform that contains a vulnerability where field-level read permissions are not properly enforced across its GraphQL and REST filter predicates. As a result, a workspace member or API key with certain permissions can exploit this oversight to reference fields that should be restricted. This can lead to an exposure of sensitive data through boolean/count oracles, allowing unauthorized reconstruction of denied field values. This issue has been addressed in version 2.22.0 of Twenty.

Affected Version(s)

twenty < 2.22.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.