CVE 6.9 MEDIUM

Teable – Unauthenticated Hidden Field Disclosure via Projection Parameter Override_CVE-2026-56781

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attackers to access hidden field data by supplying arbitrary field IDs in the projection parameter of the share view records endpoint. Attackers can enumerate hidden field IDs from share metadata and specify them in projection parameters to read field values that are intended to be restricted from public view.

Basic Information

ID CVE-2026-56781
Source VulnCheck
Published Jun 29, 2026 at 17:15

Affected Product

Vendor teableio
Product teable
Affected Versions teableio teable 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.