Improper Authentication Vulnerability in Baserow by Baserow
CVE-2026-18816

2.3LOW

Key Information:

Vendor

Baserow

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-18816?

A vulnerability exists in Baserow versions up to 2.3.2 related to the two-factor authentication (2FA) verification process. Specifically, the flaw resides in the 'verify' function located in the backend source file responsible for managing 2FA. This vulnerability enables remote exploitation, where an attacker can bypass the authentication mechanism, posing significant security risks. The complexity of exploiting this vulnerability is high, indicating that it may require advanced skills to execute. Users are strongly advised to upgrade to version 2.3.3, which addresses this issue promptly, as the vendor responded swiftly and released a patch to rectify the vulnerability.

Affected Version(s)

Baserow 2.3.0

Baserow 2.3.1

Baserow 2.3.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

GalaxynX (VulDB User)
VulDB CNA Team
.