Improper Authorization in Twenty - CVE-2026-85055
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper authorization in field-level read permission enforcement for filter predicates when processing filter queries. A remote user can use string operators in filters to infer protected field values through row-presence and total-count results to disclose sensitive information.
Only records exposed by the user\'s row-level policy are affected.