VYPR
Medium severity6.5NVD Advisory· Published Sep 16, 2026

CVE-2026-92771

CVE-2026-92771

Description

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but canReadFieldValue false can retrieve restricted field values through the groupBy resolver that would normally be denied.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Twentyhq/Twentyreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <2.35.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.