CVE-2026-86120

APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can write attachments to private datasheets they have been explicitly denied access to by exploiting the unhandled exception in the permission guard.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-05 10:16

Updated : 2026-09-08 19:20


NVD link : CVE-2026-86120

Mitre link : CVE-2026-86120

CVE.ORG link : CVE-2026-86120


JSON object : View

Products Affected

No product.

CWE
CWE-636

Not Failing Securely ('Failing Open')