Sign-In Timing Vulnerability in NocoDB Affects User Authentication
CVE-2026-47380

6.3MEDIUM

Key Information:

Vendor

Nocodb

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-47380?

NocoDB, a platform that combines database functionality with spreadsheet capabilities, experienced a vulnerability affecting its user authentication process. Before the release of version 2026.04.1, the system's sign-in response timing exhibited discrepancies between known and unknown email addresses. This issue arose because the process for handling unknown users returned results without conducting a necessary password hash comparison. Such a flaw could lead to potential exploitation by malicious actors seeking to determine valid email addresses in the system. The vulnerability has been addressed in version 2026.04.1, emphasizing the importance of timely software updates to maintain user security.

Affected Version(s)

nocodb < 2026.04.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.