github.com
https://github.com/nocodb/nocodb CVE-2026-47381
MEDIUM
NocoDB: Cross-Workspace Integration Use in Connection Test
Record summary
CVE-2026-47381 has a selected CVSS score of 6.9 (medium).
Description
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a user in one workspace could exercise another workspace's integration through the testConnection endpoint by supplying its ID, because the integration was fetched in a bypass scope and the caller's permission check matched any base in any workspace. This vulnerability is fixed in 2026.05.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 24, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
nocodbBrowse nocodb / nocodb | CVE List | < 2026.05.1 | affected |
nocodbBrowse npm / nocodb | GitHub Advisory | Before 2026.05.1 · Fixed in 2026.05.1 | affected |
References
4github.com
https://github.com/nocodb/nocodb/releases/tag/2026.05.1 github.comConfirmation
https://github.com/nocodb/nocodb/security/advisories/GHSA-96fh-m4r8-6v9v nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-47381