Apitable · Apitable · CVE-2026-84485
**Name of the Vulnerable Software and Affected Versions**
APITable versions prior to 1.13.0-beta.1
**Description**
The software exposes the internal organization 'loadOrSearch' endpoint without authentication. This allows unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. By querying the endpoint with space identifiers obtained from shared links or public templates, attackers can enumerate the complete member directory of any workspace.
**Recommendations**
Update to a version later than 1.13.0-beta.1.
As a temporary mitigation, restrict access to the 'loadOrSearch' endpoint.