SQL Injection Vulnerability in NocoDB Software
CVE-2026-47384

5.3MEDIUM

Key Information:

Vendor

Nocodb

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-47384?

NocoDB, a software tool for creating databases using spreadsheet-like interfaces, was found to have a vulnerability that allows authenticated users with column-create permissions to perform an SQL injection attack. By manipulating the title of a column to include a SQL fragment, these users can bypass existing security mechanisms and execute arbitrary SQL commands through the bulk groupBy endpoint. This issue arises due to improper handling of user input in the query building process, particularly in how it interpolates the column name directly into the SQL string. The vulnerability was remediated in version 2026.05.1.

Affected Version(s)

nocodb < 2026.05.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.