PT-2026-94049 · Git+1 · Twenty

·

CVE-2026-92771

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Twenty versions prior to 2.35.0
Description Authenticated users can bypass permission checks due to a failure to validate field and row permissions in the groupBy-with-records GraphQL resolver. An attacker possessing the canReadObjectRecords permission, but lacking the canReadFieldValue permission, can retrieve restricted field values through the groupBy resolver that would otherwise be denied.
Recommendations Update to version 2.35.0 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92771

Affected Products

Twenty