SB20260728109 - Authorization bypass through user-controlled key in Twenty



SB20260728109 - Authorization bypass through user-controlled key in Twenty

Published: July 28, 2026

Security Bulletin ID SB20260728109
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-55583)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information and modify data across workspaces.

The vulnerability exists due to improper access control in AgentTurnResolver and agent-turn-grader.service.ts when handling agentTurns(agentId) and evaluateAgentTurn(turnId) requests. A remote user can supply an agentId or turnId from another workspace to disclose sensitive information and modify data across workspaces.

User interaction is required to obtain the target identifiers, such as through browser history or screenshots from the target workspace. Exploitation is limited to instances with multi-workspace support enabled and requires the AI settings flag.


Remediation

Install update from vendor's website.