


Perceptive Security
SOC/SIEM Consultancy

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve me…
Published:
2 September 2026 at 00:00:00
Alert date:
2 September 2026 at 05:01:30
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Data Breach & Exfiltration, Enterprise Applications
APITable versions through 1.13.0-beta.1 expose an internal organization loadOrSearch endpoint without any authentication requirement. Unauthenticated attackers can exploit this vulnerability to retrieve sensitive information including member names, email addresses, and team hierarchy structures. The attack vector requires only a space identifier, which can be obtained from publicly shared links or public templates. This allows attackers to enumerate the complete member directory of any workspace. The vulnerability resides in the InternalOrganizationController and is related to missing authentication checks in the ResourceInterceptor. The flaw represents a significant information disclosure risk for organizations using APITable. No authentication or special privileges are required to exploit this issue.
Technical details
Mitigation steps:
Affected products:
APITable 1.13.0-beta.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84485
https://github.com/apitable/apitable
https://github.com/apitable/apitable/blob/88b24ce9f359cc434778be75d03603182882dc76/backend-server/application/src/main/java/com/apitable/internal/controller/InternalOrganizationController.java#L58
https://github.com/apitable/apitable/blob/88b24ce9f359cc434778be75d03603182882dc76/backend-server/application/src/main/java/com/apitable/shared/context/LoginContext.java
https://github.com/apitable/apitable/blob/88b24ce9f359cc434778be75d03603182882dc76/backend-server/application/src/main/java/com/apitable/shared/interceptor/ResourceInterceptor.java#L85
https://www.vulncheck.com/advisories/apitable-through-1.13.0-beta.1-missing-authentication-on-the-internal-organization-load-or-search-endpoint
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
