high · CVSS v3 6.5
CVE-2026-77169
A authorization bypass vulnerability exists in the team folders app when used alongside the workspace app. This flaw allows API-only delegat
Overview
A authorization bypass vulnerability exists in the team folders app when used alongside the workspace app. This flaw allows API-only delegated administrators to circumvent folder-level access restrictions. It matters because it undermines multi-tenant isolation and administrative privilege boundaries.
Description
A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management via API/REST only, restricting access to folders for which the admin has advanced permissions.
Impact
This issue impacts the confidentiality and integrity of data stored within restricted team folders. API-only delegated administrators can gain unauthorized access to folders outside their assigned advanced permissions scope. The blast radius is limited to organizations utilizing both apps concurrently with delegated REST administration.
Remediation
Apply the latest security updates provided by the vendor for both the team folders and workspace apps. Audit existing delegated administrator accounts and their API access permissions. Review access control lists and restrict REST API capabilities until patches are fully deployed.
Risk context
The vulnerability is rated as high severity with a CVSS v3 score of 6.5. EPSS data is currently not available. Organizations using the combination of team folders and workspace apps via API should prioritize remediation to maintain compliance and data privacy.
Affected products
- team folders app
- workspace app
Scores
- Severity
- high
- CVSS v2
- 7.7
- CVSS v3
- 6.5
- CVSS v4
- —
- EPSS
- —