CVE-2026-88898 Details
Description
AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs.
A vulnerability exists in the AppFlowy-Cloud application, specifically in versions 0.7.2 through 0.9.64. The issue arises in the bulk publish endpoint, where the application fails to properly authorize users against their respective workspaces. This oversight allows authenticated users to publish content into the namespaces of other tenants. Exploitation of this vulnerability enables attackers to create published views with customized titles, bodies, and metadata in the workspaces of victims, potentially defacing public pages or hosting phishing content on trusted URLs.
Users are advised to upgrade to the latest version of AppFlowy-Cloud, as this vulnerability has been addressed in the commercial fork of the application. Instructions for upgrading can be found in the AppFlowy Self-Hosted Cloud documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 10, 2026CISA-ADP
Assessed Sep 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AppFlowy-Cloud | >= 0.7.2, <= 0.9.64 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2026 | New CVE Received | [email protected] |
Volerion