Twenty CRM AI agent monitor IDOR exposed cross-workspace chat history (CVE-2026-55583)
Prior to version 2.9.0, Twenty's AI agent monitor AgentTurnResolver looked up agent turns by agentId/turnId without checking workspaceId, allowing any authenticated user with the AI settings flag to read another workspace's full AI agent chat history, including raw chat text, tool calls and tool outputs, and to trigger evaluations on the victim's turns. The issue is fixed in Twenty 2.9.0.
Disclosed 24 June 2026 · Record updated 13 September 2026
Impact
Cross-workspace insecure direct object reference permitted disclosure of another workspace's AI agent chat history (messages, tool calls, tool outputs) and insertion of evaluation rows under the victim's workspaceId, feeding victim data to the default LLM.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55583
