SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-59262

MEDIUM · CVSS 6.5 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability in AFFiNE's histories GraphQL field allows authenticated users to bypass Doc.Read permission checks, enabling them to access sensitive document edit histories, including user names, emails, and timestamps. This exposure of restricted content poses a risk to user privacy and data integrity. Organizations using AFFiNE should prioritize addressing this issue to protect their sensitive information from unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59262
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted content timelines. Attackers can supply arbitrary document GUIDs to access full edit histories including user names, emails, and timestamps of private pages they lack access to.