Medium severity6.5NVD Advisory· Published Sep 16, 2026
CVE-2026-92771
CVE-2026-92771
Description
Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but canReadFieldValue false can retrieve restricted field values through the groupBy resolver that would normally be denied.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/twentyhq/twenty/blob/twenty/v2.14.0/packages/twenty-server/src/engine/api/graphql/graphql-query-runner/group-by/services/group-by-with-records.service.tsnvd
- github.com/twentyhq/twenty/blob/twenty/v2.14.0/packages/twenty-server/src/engine/twenty-orm/repository/permissions.utils.tsnvd
- github.com/twentyhq/twenty/issues/25911nvd
- www.vulncheck.com/advisories/twenty-before-2.35.0-permission-bypass-via-groupby-with-records-querynvd
News mentions
0No linked articles in our index yet.