Authorization bypass through user-controlled key in Twenty - CVE-2026-55583

 

Authorization bypass through user-controlled key in Twenty - CVE-2026-55583

Published: July 28, 2026


Vulnerability identifier: #VU139924
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55583
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify data across workspaces.

The vulnerability exists due to improper access control in AgentTurnResolver and agent-turn-grader.service.ts when handling agentTurns(agentId) and evaluateAgentTurn(turnId) requests. A remote user can supply an agentId or turnId from another workspace to disclose sensitive information and modify data across workspaces.

User interaction is required to obtain the target identifiers, such as through browser history or screenshots from the target workspace. Exploitation is limited to instances with multi-workspace support enabled and requires the AI settings flag.


Affected software

Twenty

How to mitigate CVE-2026-55583

Install security update from vendor's website.

Twenty - update to 2.9.0

External References

Related Security Bulletins