SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-84485

HIGH · CVSS 7.5 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

APITable versions up to 1.13.0-beta.1 are vulnerable due to an unauthenticated exposure of the internal loadOrSearch endpoint, enabling attackers to access sensitive information such as member names, email addresses, and team hierarchy. This vulnerability allows for the enumeration of the complete member directory of any workspace using space identifiers from shared links or public templates. Organizations utilizing APITable should prioritize remediation to protect their user data and prevent unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84485
Severity
HIGH
CVSS
7.5
EPSS
0.35%

Original NVD Description

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.