SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-88898

MEDIUM · CVSS 6.5 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

AppFlowy-Cloud versions 0.7.2 through 0.9.64 are vulnerable due to inadequate authorization checks in the bulk publish endpoint, enabling authenticated users to publish content in other tenants' namespaces. This flaw allows attackers to manipulate published views, potentially defacing public pages or deploying phishing content under trusted URLs. Organizations using affected versions should prioritize remediation to prevent unauthorized content manipulation and protect their users from phishing attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88898
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%

Original NVD Description

AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs.