CVE-2026-24766

MEDIUM

Nocodb < 0.301.0 - Prototype Pollution

Title source: rule
STIX 2.1

Description

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-level-creator permissions can exploit prototype pollution in the `/api/v2/meta/connection/test` endpoint, causing all database write operations to fail application-wide until server restart. While the pollution technically bypasses SUPER_ADMIN authorization checks, no practical privileged actions can be performed because database operations fail immediately after pollution. Version 0.301.0 patches the issue.

Scores

CVSS v3 4.9
EPSS 0.0017
EPSS Percentile 38.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1321
Status published
Products (2)
nocodb/nocodb < 0.301.0
npm/nocodb 0 - 0.301.0npm
Published Jan 28, 2026
Tracked Since Feb 18, 2026