<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:appflowy:appflowy_cloud:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aappflowyappflowy_cloud/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 15:27:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aappflowyappflowy_cloud/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in AppFlowy-Cloud</title><link>https://feed.craftedsignal.io/briefs/2026-09-appflowy-idor/</link><pubDate>Fri, 04 Sep 2026 15:27:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-appflowy-idor/</guid><description>AppFlowy-Cloud version 0.9.64 is susceptible to an insecure direct object reference (IDOR) vulnerability that allows unauthorized cross-workspace data access and modification.</description><content:encoded><![CDATA[<p>AppFlowy-Cloud version 0.9.64 contains a critical authorization flaw where the application fails to adequately verify that a requested collaborative object is associated with the user's specific workspace. This vulnerability functions as an insecure direct object reference (IDOR), enabling an authenticated attacker to access, modify, or delete sensitive documents and database rows belonging to other workspaces. By manipulating the object ID requests sent to the server, an attacker can bypass intended access controls. The failure to validate ownership at the authorization layer is a significant security concern for multi-tenant environments, as it allows for unauthorized data exfiltration and integrity compromise across organizational boundaries.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthorized users to read, modify, or delete data stored in any workspace within an AppFlowy-Cloud instance. This leads to total loss of data confidentiality and integrity for targeted workspaces. Impact is high for organizations relying on AppFlowy-Cloud for collaborative documentation and database management.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for teams using AppFlowy-Cloud:</p>
<ul>
<li>Identify and audit the use of AppFlowy-Cloud version 0.9.64 within the enterprise environment.</li>
<li>Upgrade to a secure version of AppFlowy-Cloud that remediates CVE-2026-85619 once provided by the vendor.</li>
<li>Implement strict egress monitoring on web application traffic to detect unusual access patterns to collaborative object endpoints.</li>
<li>Configure WAF rules to scrutinize API requests targeting collaborative object IDs that deviate from established user session baselines.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>web-application</category></item></channel></rss>