PT-2026-82223 · Midday · Midday

·

CVE-2026-81035

·

Published

2026-08-26

·

Updated

2026-08-27

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Midday (affected versions not specified)
Description An authorization flaw exists in the team management logic where the system fails to verify the user role during team deletion and updates. The delete procedure in the apps/api/src/trpc/routers/team.ts file uses a team-access helper that grants access to any member regardless of their role, instead of restricting the action to the owner. This allows any invited user with the Member role to delete the entire team and all associated records. Furthermore, the deletion process triggers a cleanup job that utilizes stored bank-connection tokens against connected providers. The update procedure within the same router also lacks the necessary role verification.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81035

Affected Products

Midday