Box Team Folder API Bypass via Workspace App Delegated Admin
CVE-2026-77169 Published on September 18, 2026
A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management via API/REST only, restricting access to folders for which the admin has advanced permissions.
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-77169 has been classified to as an Authorization vulnerability or weakness.
Affected Versions
Nextcloud Team Folders:- Version 13.0.0 and below 22.0.0 is affected.