Impact
Teable before the release dated 2026-06-15T04-43-24Z.1912 contains an improper access control flaw that lets anonymous users read field values that should be hidden. By sending arbitrary field identifiers in the projection parameter of the share view records endpoint, an attacker can enumerate hidden field IDs from share metadata and retrieve field contents that are intended to remain restricted. The weakness is a classic example of missing authorization control, represented by CWE‑639.
Affected Systems
The affected product is Teable from teableio. All releases prior to the release tagged 2026-06-15T04-43-24Z.1912 are vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability with a moderate impact on confidentiality. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers only need unauthenticated network access to the share view records endpoint, and can easily construct requests with arbitrary projection parameters to extract hidden field data. No complex prerequisites are described, so the likelihood of exploitation is considered moderate to high in environments that expose the endpoint to the internet.
OpenCVE Enrichment