rootpwn

high · CVSS v3 6.5

CVE-2026-77169

A authorization bypass vulnerability exists in the team folders app when used alongside the workspace app. This flaw allows API-only delegat

Overview

A authorization bypass vulnerability exists in the team folders app when used alongside the workspace app. This flaw allows API-only delegated administrators to circumvent folder-level access restrictions. It matters because it undermines multi-tenant isolation and administrative privilege boundaries.

Description

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management via API/REST only, restricting access to folders for which the admin has advanced permissions.

Impact

This issue impacts the confidentiality and integrity of data stored within restricted team folders. API-only delegated administrators can gain unauthorized access to folders outside their assigned advanced permissions scope. The blast radius is limited to organizations utilizing both apps concurrently with delegated REST administration.

Remediation

Apply the latest security updates provided by the vendor for both the team folders and workspace apps. Audit existing delegated administrator accounts and their API access permissions. Review access control lists and restrict REST API capabilities until patches are fully deployed.

Risk context

The vulnerability is rated as high severity with a CVSS v3 score of 6.5. EPSS data is currently not available. Organizations using the combination of team folders and workspace apps via API should prioritize remediation to maintain compliance and data privacy.

Affected products

  • team folders app
  • workspace app

Scores

Severity
high
CVSS v2
7.7
CVSS v3
6.5
CVSS v4
EPSS

authorization-bypass api-security access-control delegated-admin high-severity

← All CVEs