CVE-2026-88898
AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- CWE
- CWE-862
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- AppFlowy-IO AppFlowy-Cloud
Weakness type
Related vulnerabilities
- CVE-2026-89054 — OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes
- CVE-2026-88959 — Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints
- CVE-2026-4129 — Improper Access Controls in NI SystemLink
- CVE-2026-84821 — WordPress WP Fast Total Search plugin <= 1.82.284 - Broken Access Control vulnerability
- CVE-2026-81801 — WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability
- CVE-2026-81799 — WordPress Return Refund and Exchange For WooCommerce plugin <= 4.6.4 - Broken Access Control vulnerability
- CVE-2026-81794 — WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access Control vulnerability
- CVE-2026-81793 — WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vulnerability