File Access Vulnerability in NocoDB by NocoDB
CVE-2026-47388
2.3LOW
What is CVE-2026-47388?
A vulnerability in NocoDB, prior to version 2026.05.1, allows a low-privilege user holding an MCP token to read any file in shared storage, including attachments from different bases and workspaces. This occurs due to insufficient verification of file ownership in the MCP readAttachment tool, potentially exposing sensitive data to unauthorized users.
Affected Version(s)
nocodb < 2026.05.1
