PatchSiren

apitable CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH apitable CVE published 2026-09-02

CVE-2026-84485

CVE-2026-84485 is a high-severity vulnerability in APITable through 1.13.0-beta.1 that exposes an internal organization loadOrSearch endpoint without authentication. This allows unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. The vulnerability has a CVSS score of 8.7 and is considered high severity. Affected deployments should prioritize verifying exposure and ensu [truncated]

HIGH apitable CVE published 2026-08-27

CVE-2026-80208

CVE-2026-80208 is a high-severity vulnerability in APITable through 1.13.0-beta.1. The vulnerability allows unauthenticated clients to bypass the 30-day cooling-off period after a user deletion request, leading to permanent account deletion and data loss. This could result in significant data loss for APITable users if exploited. Defenders responsible for APITable instances, particularly those with expose [truncated]

MEDIUM apitable CVE published 2026-08-27

CVE-2026-80207

CVE-2026-80207 is a medium-severity vulnerability in APITable through 1.13.0-beta.1. An unauthenticated attacker can create arbitrary notifications in apitable_player_notification against any user ID, which are stored with the system sender and rendered in the victim's inbox as legitimate system notifications. This vulnerability allows an attacker to persist notifications with arbitrary content, posing a [truncated]