Access Control Vulnerability in NocoDB Affects Database Privacy
CVE-2026-47279
6.9MEDIUM
What is CVE-2026-47279?
NocoDB, a tool designed to facilitate database management through a spreadsheet interface, harbored an access control vulnerability prior to version 2026.05.1. This flaw allowed unauthorized users with a share UUID to access the contents of any column, including those hidden by the view owner, due to insufficient visibility checks on the public shared-view relation endpoints. Although some validation mechanisms were in place, they failed to consider the visibility status of the columns, resulting in potential data exposure. The issue has been addressed in the 2026.05.1 update.
Affected Version(s)
nocodb < 2026.05.1
