Vulnerability Description
AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete cross-workspace data.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/AppFlowy-IO/AppFlowy-Cloud
- https://github.com/AppFlowy-IO/AppFlowy-Cloud/blob/0.9.64/libs/access-control/sr
- https://github.com/AppFlowy-IO/AppFlowy-Cloud/issues/1624
- https://www.vulncheck.com/advisories/appflowy-cloud-0.9.64-cross-workspace-colla
- https://github.com/AppFlowy-IO/AppFlowy-Cloud/issues/1624
FAQ
What is CVE-2026-85619?
CVE-2026-85619 is a vulnerability with a CVSS score of 7.5 (HIGH). AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attacke...
How severe is CVE-2026-85619?
CVE-2026-85619 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-85619?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.