Field-Level Permission Exposure in Twenty CRM
CVE-2026-85055
7.1HIGH
What is CVE-2026-85055?
Twenty is an open-source CRM platform that contains a vulnerability where field-level read permissions are not properly enforced across its GraphQL and REST filter predicates. As a result, a workspace member or API key with certain permissions can exploit this oversight to reference fields that should be restricted. This can lead to an exposure of sensitive data through boolean/count oracles, allowing unauthorized reconstruction of denied field values. This issue has been addressed in version 2.22.0 of Twenty.
Affected Version(s)
twenty < 2.22.0
