MEDIUM 6.0 NVD
CVE-2026-85622
AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing
AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticated users to bind sessions to workspaces they do not belong to. Attackers can send sync Manifest messages with victim object identifiers to read full document or database state from collaborations in other workspaces without victim involvement.
References
- https://github.com/AppFlowy-IO/AppFlowy-Cloud
- https://github.com/AppFlowy-IO/AppFlowy-Cloud/blob/0.9.64/src/api/ws.rs
- https://github.com/AppFlowy-IO/AppFlowy-Cloud/issues/1629
- https://www.vulncheck.com/advisories/appflowy-cloud-through-0.9.64-cross-workspace-collab-
This medium severity vulnerability with a CVSS score of 6.0 was published on 2026-09-04 via NVD.
vulnfeed aggregates 8217 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.