Token Ownership Validation Flaw in NocoDB Software by NocoDB
CVE-2026-28361
4.9MEDIUM
What is CVE-2026-28361?
NocoDB is a database-building software that uses a spreadsheet-like interface. Prior to version 0.301.3, it contained a vulnerability in the MCP token service where the application failed to validate token ownership correctly. This flaw allowed users designated as 'Creators' within the same database instance to manipulate another user's MCP tokens, including reading, regenerating, or deleting them if the token ID was known. This oversight poses a risk to user data integrity and privacy, and it has since been addressed in the release of version 0.301.3.
Affected Version(s)
nocodb < 0.301.3
