Description
AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete cross-workspace data.
Published: 2026-09-04
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The software version 0.9.64 of AppFlowy-Cloud does not verify that queued collaboration objects belong to the requesting workspace in its authorization checks. This flaw permits an attacker to supply a victim’s object identifier along with an attacker’s own workspace identifier, thereby bypassing collab access controls. Once bypassed, the attacker can read, modify, or delete documents and database rows that belong to other workspaces, compromising confidentiality, integrity, and availability of cross‑workspace data. The weakness is categorized as a missing or inaccurate permission check, CWE-863.

Affected Systems

AppFlowy-IO AppFlowy-Cloud version 0.9.64 is affected. No other versions or vendors are listed in the current advisory.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no public exploitation at the time of this analysis. The likely attack vector is an external network attacker using the exposed HTTP API to supply malicious requests. Because the flaw stems from missing authorization verification, any entity with network access to the API can potentially exploit it, leading to unauthorized data disclosure or modification across workspaces.

Generated by OpenCVE AI on September 4, 2026 at 15:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade AppFlowy-Cloud to the latest official release that includes the authorization fix.
  • Apply any available patch for version 0.9.64 released by AppFlowy-IO.
  • If an immediate upgrade is not possible, temporarily limit API access to trusted network segments using firewall rules or VPN to reduce exposure until the patch is applied.

Generated by OpenCVE AI on September 4, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Appflowy-io
Appflowy-io appflowy-cloud
Vendors & Products Appflowy-io
Appflowy-io appflowy-cloud

Fri, 04 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete cross-workspace data.
Title AppFlowy-Cloud 0.9.64 Cross-Workspace Collab Access via HTTP API
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Appflowy-io Appflowy-cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-04T17:56:11.229Z

Reserved: 2026-09-04T11:03:33.315Z

Link: CVE-2026-85619

cve-icon Vulnrichment

Updated: 2026-09-04T17:56:07.283Z

cve-icon NVD

Status : Received

Published: 2026-09-04T15:17:42.003

Modified: 2026-09-04T18:18:04.773

Link: CVE-2026-85619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:30:07Z

Weaknesses