Team Folders vulnerability

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management via API/REST only, restricting access to folders for which the admin has advanced permissions.

Published 18 Sep 2026Updated 18 Sep 20261 sources
CVSS 6.5

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.