CVE-2026-92771 PUBLISHED

Twenty before 2.35.0 Permission Bypass via groupBy-with-records Query

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but canReadFieldValue false can retrieve restricted field values through the groupBy resolver that would normally be denied.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor twentyhq
Product twenty
Versions Default: unaffected
  • affected from 0 to 2.35.0 (excl.)

Credits

  • George Chen finder

References

Problem Types

  • Incorrect Authorization CWE