PT-2026-94049 · Git+1 · Twenty
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Twenty versions prior to 2.35.0
Description
Authenticated users can bypass permission checks due to a failure to validate field and row permissions in the
groupBy-with-records GraphQL resolver. An attacker possessing the canReadObjectRecords permission, but lacking the canReadFieldValue permission, can retrieve restricted field values through the groupBy resolver that would otherwise be denied.Recommendations
Update to version 2.35.0 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Twenty