Database Integration Bypass in NocoDB Software
CVE-2026-47381
6.9MEDIUM
What is CVE-2026-47381?
NocoDB, a platform for creating databases with a spreadsheet interface, is susceptible to an access control bypass vulnerability. In versions prior to 2026.05.1, a user from one workspace could exploit the testConnection endpoint to gain unauthorized access to integrations in another workspace by simply providing its ID. This occurs due to inadequate permission checks that allow access across different workspaces. The issue is resolved in version 2026.05.1, which strengthens access controls.
Affected Version(s)
nocodb < 2026.05.1
