Improper Authorization Vulnerability in Baserow by Baserow Team
CVE-2026-18817

2.1LOW

Key Information:

Vendor

Baserow

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-18817?

A security flaw has been identified in Baserow affecting versions up to 2.3.2, related to the BaserowImpersonateAuthTokenSerializer function. This vulnerability occurs in the Inactive Non-Staff User Handler component, where a manipulation may lead to improper authorization. Although remote exploitation is feasible, the complexity of the attack is considerably high, making it challenging to exploit. Feedback from the project maintainer suggests that while the issue is acknowledged, it may resemble a bug rather than a traditional vulnerability, as deactivated user endpoints currently do not operate effectively. Users are advised to upgrade to version 2.3.3 to mitigate this issue.

Affected Version(s)

Baserow 2.3.0

Baserow 2.3.1

Baserow 2.3.2

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

GalaxynX (VulDB User)
VulDB CNA Team
.