Skip to content
Threat Feed
high advisory

Authorization Bypass in AppFlowy-Cloud

AppFlowy-Cloud version 0.9.64 is susceptible to an insecure direct object reference (IDOR) vulnerability that allows unauthorized cross-workspace data access and modification.

CVE search metadata

CVE search record: CVE-2026-85619. Severity: high. CVSS: 7.5. KEV: no. Product: AppFlowy-Cloud (0.9.64). Brief: Authorization Bypass in AppFlowy-Cloud. Brief link: https://feed.craftedsignal.io/briefs/2026-09-appflowy-idor/

AppFlowy-Cloud version 0.9.64 contains a critical authorization flaw where the application fails to adequately verify that a requested collaborative object is associated with the user's specific workspace. This vulnerability functions as an insecure direct object reference (IDOR), enabling an authenticated attacker to access, modify, or delete sensitive documents and database rows belonging to other workspaces. By manipulating the object ID requests sent to the server, an attacker can bypass intended access controls. The failure to validate ownership at the authorization layer is a significant security concern for multi-tenant environments, as it allows for unauthorized data exfiltration and integrity compromise across organizational boundaries.

Impact

Successful exploitation allows unauthorized users to read, modify, or delete data stored in any workspace within an AppFlowy-Cloud instance. This leads to total loss of data confidentiality and integrity for targeted workspaces. Impact is high for organizations relying on AppFlowy-Cloud for collaborative documentation and database management.

Recommendation

Prioritized, concrete actions for teams using AppFlowy-Cloud:

  • Identify and audit the use of AppFlowy-Cloud version 0.9.64 within the enterprise environment.
  • Upgrade to a secure version of AppFlowy-Cloud that remediates CVE-2026-85619 once provided by the vendor.
  • Implement strict egress monitoring on web application traffic to detect unusual access patterns to collaborative object endpoints.
  • Configure WAF rules to scrutinize API requests targeting collaborative object IDs that deviate from established user session baselines.

Immediate actions

Upgrade AppFlowy-Cloud to a patched version beyond 0.9.64

IT Operations 48h

Mitigations

Upgrade AppFlowy-Cloud to remediate CVE-2026-85619

immediate IT Operations

CVE-2026-85619