Improper Authorization in APITable's NodePermissionGuard Affects User Data Security
CVE-2026-86120

5.3MEDIUM

Key Information:

Vendor

Apitable

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86120?

APITable versions up to 1.13.0-beta.1 are susceptible to an authorization flaw within the NodePermissionGuard. This vulnerability permits attackers with valid Fusion API tokens to bypass intended access controls when the system encounters permission lookup exceptions. As a result, malicious users can write unauthorized attachments to private datasheets from which they would typically be denied access. This exploit occurs due to the failure in exception handling within the guard, highlighting critical security implications for data integrity and confidentiality.

Affected Version(s)

apitable 0 <= 1.13.0-beta.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.