Impact
The vulnerability allows an authenticated user who has read permissions for object records but lacks the ability to read specific field values to retrieve those restricted values through the groupBy-with-records GraphQL resolver. Because the resolver skips validation of field and row permissions, the attacker can access data that should be denied, effectively bypassing the platform’s read control mechanism. This flaw stems from incorrect permission enforcement (CWE-863).
Affected Systems
The affected product is twentyhq’s twenty application. Any deployment running a version earlier than 2.35.0 is vulnerable, including but not limited to the 2.14.0 release referenced in the advisory. Systems that expose the GraphQL API and use the groupBy queries are susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk of compromise. The EPSS score is less than 1%, suggesting a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, exploitation requires an authenticated user with the canReadObjectRecords permission. The attacker can query the groupBy endpoint, provide a request that triggers the bug, and extract restricted field values without needing elevated privileges. The combination of these conditions makes the risk moderate to high for affected installations.
OpenCVE Enrichment