CVE-2026-86120CWE-636

CVE-2026-86120

Medium · published September 5, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
11.6
In the wild
Unconfirmed
What it is

APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can write attachments to private datasheets they have been explicitly denied access to by exploiting the unhandled exception in the permission guard.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS
0.00214 · 11.6th percentile
Weakness
CWE-636 · Not Failing Securely ('Failing Open')
Published
2026-09-05T14:16Z
References (4)
EPSS history
Timeline
  • 07 SEP 03:36Z
    EPSS moved — → 0%
    epss
  • 05 SEP 09:59Z
    APITable through 1.13.0-beta.1 Fail-Open Authorization in the Fusion API Node Permission Guard
    cvelistv5