Box Team Folder API Bypass via Workspace App Delegated Admin
CVE-2026-77169 Published on September 18, 2026

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management via API/REST only, restricting access to folders for which the admin has advanced permissions.

NVD

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2026-77169 has been classified to as an Authorization vulnerability or weakness.


Affected Versions

Nextcloud Team Folders: