Description
Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but canReadFieldValue false can retrieve restricted field values through the groupBy resolver that would normally be denied.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access via permission bypass
Action: Patch immediately
AI Analysis

Impact

The vulnerability allows an authenticated user who has read permissions for object records but lacks the ability to read specific field values to retrieve those restricted values through the groupBy-with-records GraphQL resolver. Because the resolver skips validation of field and row permissions, the attacker can access data that should be denied, effectively bypassing the platform’s read control mechanism. This flaw stems from incorrect permission enforcement (CWE-863).

Affected Systems

The affected product is twentyhq’s twenty application. Any deployment running a version earlier than 2.35.0 is vulnerable, including but not limited to the 2.14.0 release referenced in the advisory. Systems that expose the GraphQL API and use the groupBy queries are susceptible.

Risk and Exploitability

The CVSS score of 7.1 indicates a high risk of compromise. The EPSS score is less than 1%, suggesting a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, exploitation requires an authenticated user with the canReadObjectRecords permission. The attacker can query the groupBy endpoint, provide a request that triggers the bug, and extract restricted field values without needing elevated privileges. The combination of these conditions makes the risk moderate to high for affected installations.

Generated by OpenCVE AI on September 18, 2026 at 06:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the twenty application to version 2.35.0 or later to apply the vendor‑provided fix.
  • Restrict the use of groupBy queries in GraphQL endpoints or add additional checks that enforce row and field permissions explicitly.
  • Review and adjust permission assignments so that users who can read object records also have the necessary field read permissions or are denied access to groupBy functionality until the patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 06:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but canReadFieldValue false can retrieve restricted field values through the groupBy resolver that would normally be denied.
Title Twenty before 2.35.0 Permission Bypass via groupBy-with-records Query
First Time appeared Twenty
Twenty twenty
Weaknesses CWE-863
CPEs cpe:2.3:a:twenty:twenty:*:*:*:*:*:*:*:*
Vendors & Products Twenty
Twenty twenty
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T18:31:26.228Z

Reserved: 2026-09-16T19:15:38.662Z

Link: CVE-2026-92771

cve-icon Vulnrichment

Updated: 2026-09-18T18:31:18.596Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:25.750

Modified: 2026-09-23T17:17:48.260

Link: CVE-2026-92771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses