PT-2026-84587 · Apitable · Apitable
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
APITable versions prior to 1.13.0-beta.1
Description
The software exposes the internal organization 'loadOrSearch' endpoint without authentication. This allows unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. By querying the endpoint with space identifiers obtained from shared links or public templates, attackers can enumerate the complete member directory of any workspace.
Recommendations
Update to a version later than 1.13.0-beta.1.
As a temporary mitigation, restrict access to the 'loadOrSearch' endpoint.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apitable