{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/apitable/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-80208"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["APITable"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","web-application-vulnerability","data-destruction"],"_cs_type":"threat","_cs_vendors":["APITable"],"content_html":"\u003cp\u003eAPITable versions up to and including 1.13.0-beta.1 contain an authentication bypass vulnerability in the \u003ccode\u003eInternalUserController\u003c/code\u003e class. The endpoints \u003ccode\u003egetUserHistories\u003c/code\u003e and \u003ccode\u003eclosePausedUserAccount\u003c/code\u003e are incorrectly annotated with \u003ccode\u003erequiredLogin = false\u003c/code\u003e. The application's \u003ccode\u003eResourceInterceptor\u003c/code\u003e honors this annotation by skipping session or API key validation for these routes. Because the product's bundled nginx gateway proxies all \u003ccode\u003e/api\u003c/code\u003e requests to the backend, these sensitive administrative functions are exposed to any unauthenticated client with network access to the gateway. An attacker can exploit this to enumerate accounts awaiting permanent deletion and finalize the removal process, thereby bypassing the 30-day account recovery cooling-off period. This leads to irreversible data loss for targeted users.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify an APITable instance reachable via HTTP/HTTPS.\u003c/li\u003e\n\u003cli\u003eAttacker probes the \u003ccode\u003e/api/v1/internal/\u003c/code\u003e path to determine if the \u003ccode\u003eInternalUserController\u003c/code\u003e endpoints are exposed without authentication.\u003c/li\u003e\n\u003cli\u003eAttacker sends a POST request to \u003ccode\u003e/api/v1/internal/getUserHistories\u003c/code\u003e to retrieve a list of all user accounts currently in a 30-day cooling-off (deleted/paused) state.\u003c/li\u003e\n\u003cli\u003eAttacker parses the response to extract valid \u003ccode\u003euserId\u003c/code\u003e values for the identified target accounts.\u003c/li\u003e\n\u003cli\u003eAttacker iterates through the collected \u003ccode\u003euserId\u003c/code\u003e values.\u003c/li\u003e\n\u003cli\u003eAttacker sends a POST request to \u003ccode\u003e/api/v1/internal/users/{userId}/close\u003c/code\u003e for each identified account.\u003c/li\u003e\n\u003cli\u003eThe backend processes the closure, clearing PII, canceling subscriptions, and deleting OAuth bindings.\u003c/li\u003e\n\u003cli\u003eAccount recovery is successfully prevented, resulting in permanent data destruction for the targeted user.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the permanent loss of user accounts that are otherwise protected by a 30-day recovery window. This vulnerability impacts the integrity and availability of user data within the APITable platform. While the scope of impact depends on the number of accounts currently in the cooling-off period, unauthorized access to administrative internal APIs constitutes a critical breach of the platform's security boundary.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement monitoring on web server logs for HTTP POST requests to \u003ccode\u003e/api/v1/internal/\u003c/code\u003e originating from untrusted or non-administrative source IPs.\u003c/li\u003e\n\u003cli\u003ePatch APITable to a version beyond 1.13.0-beta.1 that corrects the \u003ccode\u003erequiredLogin\u003c/code\u003e annotation for the \u003ccode\u003eInternalUserController\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the \u003ccode\u003e/api/v1/internal/\u003c/code\u003e path at the nginx gateway or firewall level to ensure only authorized management IPs can access these administrative endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T19:10:05Z","date_published":"2026-08-27T19:10:05Z","id":"https://feed.craftedsignal.io/briefs/2026-08-apitable-auth-bypass/","summary":"APITable versions up to 1.13.0-beta.1 contain an authentication bypass vulnerability in the InternalUserController, allowing unauthenticated attackers to permanently delete user accounts currently in a cooling-off period.","title":"Authentication Bypass in APITable InternalUserController","url":"https://feed.craftedsignal.io/briefs/2026-08-apitable-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - APITable","version":"https://jsonfeed.org/version/1.1"}