Improper Authorization Vulnerability in Baserow by Baserow Team
CVE-2026-18817
2.1LOW
What is CVE-2026-18817?
A security flaw has been identified in Baserow affecting versions up to 2.3.2, related to the BaserowImpersonateAuthTokenSerializer function. This vulnerability occurs in the Inactive Non-Staff User Handler component, where a manipulation may lead to improper authorization. Although remote exploitation is feasible, the complexity of the attack is considerably high, making it challenging to exploit. Feedback from the project maintainer suggests that while the issue is acknowledged, it may resemble a bug rather than a traditional vulnerability, as deactivated user endpoints currently do not operate effectively. Users are advised to upgrade to version 2.3.3 to mitigate this issue.
Affected Version(s)
Baserow 2.3.0
Baserow 2.3.1
Baserow 2.3.2
