Loading market data...
← Back to CVE feed

CVE-2026-92771

MEDIUM CVSS 6.5 View on NVD ↗

Description

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but canReadFieldValue false can retrieve restricted field values through the groupBy resolver that would normally be denied.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Published: Sep 16, 2026 21:17 UTC Modified: Sep 16, 2026 21:17 UTC