User Enumeration Vulnerability in NocoDB by NocoDB Team
CVE-2026-28358
2.7LOW
What is CVE-2026-28358?
In prior versions of NocoDB, specifically before 0.301.3, a vulnerability existed within the password reset functionality. This security flaw allowed attackers to discern whether an email address was registered in the system based on differing responses from the endpoint. Such discrepancies could be exploited for user enumeration, potentially leading to further attacks on user accounts. This issue has been addressed in version 0.301.3, which effectively patches the vulnerability.
Affected Version(s)
nocodb < 0.301.3
