PT-2026-53658 · Tenable · Tenable
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Teable versions prior to 2026-06-15T04-43-24Z.1912
Description
An improper access control issue allows anonymous attackers to access hidden field data. By enumerating hidden field IDs from share metadata and supplying them in the
projection parameter of the share view records endpoint, an attacker can read field values intended to be restricted from public view.Recommendations
Update Teable to version 2026-06-15T04-43-24Z.1912 or later.
Avoid using the
projection parameter in the share view records endpoint to request restricted field IDs.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tenable