Team Folders vulnerability

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management via API/REST only, restricting access to folders for which the admin has advanced permissions.

Published 18 Sep 2026Updated 18 Sep 20261 sources
CVSS 6.5

Source timeline

CVE record published by NVDView source ↗