Database Integration Bypass in NocoDB Software
CVE-2026-47381

6.9MEDIUM

Key Information:

Vendor

Nocodb

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-47381?

NocoDB, a platform for creating databases with a spreadsheet interface, is susceptible to an access control bypass vulnerability. In versions prior to 2026.05.1, a user from one workspace could exploit the testConnection endpoint to gain unauthorized access to integrations in another workspace by simply providing its ID. This occurs due to inadequate permission checks that allow access across different workspaces. The issue is resolved in version 2026.05.1, which strengthens access controls.

Affected Version(s)

nocodb < 2026.05.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.