Description
AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs.
Published: 2026-09-10
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Publishing
Action: Patch Now
AI Analysis

Impact

The vulnerability is a missing authorization check in the bulk publish endpoint of AppFlowy-Cloud, allowing any authenticated user to publish content into any workspace’s namespace. Attackers can create published views with attacker‑controlled titles, bodies and metadata, thereby defacing public pages or hosting phishing content on trusted URLs. The impact includes loss of content integrity, potential defacement, and the ability to lure users into phishing attacks.

Affected Systems

AppFlowy-IO’s AppFlowy‑Cloud versions 0.7.2 through 0.9.64 are affected. Users deployed within this version range do not enforce workspace‑level authorization on the bulk publish endpoint and are therefore susceptible to cross‑tenant publishing.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is authenticated API requests to the bulk publish endpoint, and the weakness is identified as CWE‑862: Authorization Control.

Generated by OpenCVE AI on September 10, 2026 at 18:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AppFlowy‑Cloud to the latest supported version that enforces workspace authorization on the bulk publish endpoint.
  • If an immediate upgrade is not possible, restrict access to the bulk publish endpoint to trusted administrators via API gateway or firewall rules so that only authorized users can publish.
  • Regularly audit published content and remove any unauthorized views; consider disabling the bulk publish feature until the vulnerability is fully mitigated.

Generated by OpenCVE AI on September 10, 2026 at 18:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Appflowy-io
Appflowy-io appflowy-cloud
Vendors & Products Appflowy-io
Appflowy-io appflowy-cloud

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs.
Title AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk Publish Endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Appflowy-io Appflowy-cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T14:59:17.347Z

Reserved: 2026-09-10T11:28:50.297Z

Link: CVE-2026-88898

cve-icon Vulnrichment

Updated: 2026-09-10T14:59:07.765Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T15:17:59.107

Modified: 2026-09-10T16:18:11.997

Link: CVE-2026-88898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:00:08Z

Weaknesses