CVE-2026-86120 APITable through 1.13.0-beta.1 contains an incorrect… — CVE Notify — TG.ME

🚨 CVE-2026-86120
APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can write attachments to private datasheets they have been explicitly denied access to by exploiting the unhandled exception in the permission guard.

🎖@cveNotify
GitHub
GitHub - apitable/apitable: 🚀🎉📚 APITable, an API-oriented low-code platform for building collaborative apps and better than all…
🚀🎉📚 APITable, an API-oriented low-code platform for building collaborative apps and better than all other Airtable open-source alternatives. - apitable/apitable
September 5, 2026 13