APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can write attachments to private datasheets they have been explicitly denied access to by exploiting the unhandled exception in the permission guard.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-05 10:16
Updated : 2026-09-08 19:20
NVD link : CVE-2026-86120
Mitre link : CVE-2026-86120
CVE.ORG link : CVE-2026-86120
JSON object : View
Products Affected
No product.
CWE
CWE-636
Not Failing Securely ('Failing Open')
