Authorization Bypass in AppFlowy-Cloud Affects Multiple Workspaces
CVE-2026-85619

7.7HIGH

Key Information:

Vendor
CVE Published:
4 September 2026

What is CVE-2026-85619?

The AppFlowy-Cloud application version 0.9.64 demonstrates a critical flaw in its authorization mechanism, specifically failing to verify that requested collaborative objects are tied to the respective user’s workspace. An attacker can manipulate a victim's object ID and their own workspace ID, leading to unauthorized access that allows them to read, modify, or delete sensitive data and documents belonging to different workspaces. This poses significant data security risks to organizations relying on AppFlowy-Cloud for collaborative work.

Affected Version(s)

AppFlowy-Cloud 0 <= 0.9.64

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.