CVE-2026-84485: APITable through 1.13.0-beta.1 Missing Authentication on the Internal Organization Load or Search Endpoint
APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.
Affected Software
Event History
Frequently Asked Questions
Which workspaces are realistically exposed?
Any APITable workspace is exposed if an attacker can obtain its space identifier from a shared link or public template. The issue permits enumeration of the complete member directory for that workspace.
What does an attacker need to exploit this issue?
An attacker needs network access to the exposed endpoint and a target workspace's space identifier. No authentication, privileges, or user interaction are required.
What information can be retrieved?
An attacker can retrieve member names, email addresses, and the workspace team hierarchy. The described impact is disclosure of the complete member directory.
How can an organization assess whether it is affected?
Deployments of APITable through 1.13.0-beta.1 should be considered affected. Review whether workspace space identifiers are exposed through shared links or public templates and whether the internal organization loadOrSearch endpoint can be queried without authentication.