MEDIUMVulnerability

CVE-2026-86120

APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can write attachments to private datasheets they have been explicitly denied access to by exploiting the unhandled exception in the permission guard.

Properties

severity
MEDIUM
score
4.3
cve_id
CVE-2026-86120
signal_observed_at
2026-09-23T22:44:45+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
published_at
2026-09-05T10:16:43.307
last_modified
2026-09-23T17:17:45.150

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Not Failing Securely ('Failing Open')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86120 — Ninja Signal Threat Intelligence | Ninja Signal