Unauthenticated Data Disclosure in Baserow Application Builder
CVE-2026-81335

8.7HIGH

Key Information:

Vendor

Baserow

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81335?

The Baserow Application Builder contains a flaw where it fails to properly enforce permission checks when dispatching data sources. This allows uncredentialed requests to bypass authentication and access sensitive data. Specifically, when a request is made to dispatch a data source, the application does not raise exceptions upon permission denial, resulting in unauthorized access to the data source's rows and fields. This vulnerability poses a risk to user data integrity and confidentiality, as attackers can enumerate small integer identifiers to exploit this flaw. Affected users should update to version 2.3.1 or higher, which includes necessary security enhancements to mitigate this vulnerability.

Affected Version(s)

Baserow 0 < 2.3.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Holmquist
.