CVE-2026-28361

MEDIUM

NocoDB <0.301.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not validate token ownership, allowing a Creator within the same base to read, regenerate, or delete another user's MCP tokens if the token ID was known. This issue has been patched in version 0.301.3.

Scores

CVSS v3 6.3
EPSS 0.0005
EPSS Percentile 14.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
nocodb/nocodb < 0.301.3
npm/nocodb 0 - 0.301.3npm
Published Mar 02, 2026
Tracked Since Mar 03, 2026