PT-2026-22633 · Nocodb · Nocodb

Bugbunny-Research

·

Published

2026-03-02

·

Updated

2026-03-02

·

CVE-2026-28396

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions NocoDB versions prior to 0.301.3
Description NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset process did not invalidate existing refresh tokens. This allowed an attacker who previously obtained a refresh token to continue creating valid JSON Web Tokens (JWTs) even after the user reset their password. The password reset flow did not revoke existing refresh tokens, enabling continued access with stolen tokens.
Recommendations Update to version 0.301.3 or later.

Exploit

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2026-28396
GHSA-X4VH-J75G-268G

Affected Products

Nocodb