CVE-2026-84485: APITable through 1.13.0-beta.1 Missing Authentication on the Internal Organization Load or Search Endpoint

Published Sep 2, 2026
·
Updated

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.

Affected Software

1 affected component
APITable<=1.13.0-beta.1

Event History

Sep 2, 2026
CVE Published
via MITRE·01:18 AM
Data Sourced
via MITRE·01:18 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which workspaces are realistically exposed?

Any APITable workspace is exposed if an attacker can obtain its space identifier from a shared link or public template. The issue permits enumeration of the complete member directory for that workspace.

2

What does an attacker need to exploit this issue?

An attacker needs network access to the exposed endpoint and a target workspace's space identifier. No authentication, privileges, or user interaction are required.

3

What information can be retrieved?

An attacker can retrieve member names, email addresses, and the workspace team hierarchy. The described impact is disclosure of the complete member directory.

4

How can an organization assess whether it is affected?

Deployments of APITable through 1.13.0-beta.1 should be considered affected. Review whether workspace space identifiers are exposed through shared links or public templates and whether the internal organization loadOrSearch endpoint can be queried without authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203