Permission Bypass in Twenty Product by TwentyHQ
CVE-2026-92771

7.1HIGH

Key Information:

Vendor

Twentyhq

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92771?

The Twenty product by TwentyHQ prior to version 2.35.0 contains a vulnerability that permits authenticated users to bypass essential field and row permissions associated with the groupBy-with-records GraphQL resolver. Specifically, users equipped with the canReadObjectRecords permission, but lacking the canReadFieldValue permission, can exploit this flaw to access restricted field values that should typically be off-limits. This weakness highlights significant gaps in the application's permission validation processes, potentially exposing sensitive data to unauthorized access.

Affected Version(s)

twenty 0 < 2.35.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.