Permission Bypass in Twenty Product by TwentyHQ
CVE-2026-92771
7.1HIGH
What is CVE-2026-92771?
The Twenty product by TwentyHQ prior to version 2.35.0 contains a vulnerability that permits authenticated users to bypass essential field and row permissions associated with the groupBy-with-records GraphQL resolver. Specifically, users equipped with the canReadObjectRecords permission, but lacking the canReadFieldValue permission, can exploit this flaw to access restricted field values that should typically be off-limits. This weakness highlights significant gaps in the application's permission validation processes, potentially exposing sensitive data to unauthorized access.
Affected Version(s)
twenty 0 < 2.35.0
