PT-2026-22632 · Nocodb · Nocodb

Bugbunny-Research

·

Published

2026-03-02

·

Updated

2026-03-02

·

CVE-2026-28361

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions NocoDB versions prior to 0.301.3
Description NocoDB is software for building databases as spreadsheets. The MCP token service did not validate token ownership. This allowed a Creator within the same base to read, regenerate, or delete another user's MCP tokens if the token ID was known. The issue affects versions prior to 0.301.3.
Recommendations Update to version 0.301.3 or later.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-28361
GHSA-P9X3-W98F-7J3Q

Affected Products

Nocodb