Sign-In Timing Vulnerability in NocoDB Affects User Authentication
CVE-2026-47380
6.3MEDIUM
What is CVE-2026-47380?
NocoDB, a platform that combines database functionality with spreadsheet capabilities, experienced a vulnerability affecting its user authentication process. Before the release of version 2026.04.1, the system's sign-in response timing exhibited discrepancies between known and unknown email addresses. This issue arose because the process for handling unknown users returned results without conducting a necessary password hash comparison. Such a flaw could lead to potential exploitation by malicious actors seeking to determine valid email addresses in the system. The vulnerability has been addressed in version 2026.04.1, emphasizing the importance of timely software updates to maintain user security.
Affected Version(s)
nocodb < 2026.04.1
