{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aappflowyappflowy_cloud/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:appflowy:appflowy_cloud:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85619"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AppFlowy-Cloud (0.9.64)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["AppFlowy"],"content_html":"\u003cp\u003eAppFlowy-Cloud version 0.9.64 contains a critical authorization flaw where the application fails to adequately verify that a requested collaborative object is associated with the user's specific workspace. This vulnerability functions as an insecure direct object reference (IDOR), enabling an authenticated attacker to access, modify, or delete sensitive documents and database rows belonging to other workspaces. By manipulating the object ID requests sent to the server, an attacker can bypass intended access controls. The failure to validate ownership at the authorization layer is a significant security concern for multi-tenant environments, as it allows for unauthorized data exfiltration and integrity compromise across organizational boundaries.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized users to read, modify, or delete data stored in any workspace within an AppFlowy-Cloud instance. This leads to total loss of data confidentiality and integrity for targeted workspaces. Impact is high for organizations relying on AppFlowy-Cloud for collaborative documentation and database management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for teams using AppFlowy-Cloud:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and audit the use of AppFlowy-Cloud version 0.9.64 within the enterprise environment.\u003c/li\u003e\n\u003cli\u003eUpgrade to a secure version of AppFlowy-Cloud that remediates CVE-2026-85619 once provided by the vendor.\u003c/li\u003e\n\u003cli\u003eImplement strict egress monitoring on web application traffic to detect unusual access patterns to collaborative object endpoints.\u003c/li\u003e\n\u003cli\u003eConfigure WAF rules to scrutinize API requests targeting collaborative object IDs that deviate from established user session baselines.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:27:56Z","date_published":"2026-09-04T15:27:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-appflowy-idor/","summary":"AppFlowy-Cloud version 0.9.64 is susceptible to an insecure direct object reference (IDOR) vulnerability that allows unauthorized cross-workspace data access and modification.","title":"Authorization Bypass in AppFlowy-Cloud","url":"https://feed.craftedsignal.io/briefs/2026-09-appflowy-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:appflowy:appflowy_cloud:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}