Junglewise Threat Intelligence

CVE-2026-28358: NocoDB user enumeration via password reset endpoint

CVE-2026-28358 · Severity: medium · CVSS 4 · Published 2026-03-02

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB is an open-source database management and collaboration tool used as an Airtable alternative. An unauthenticated attacker could determine whether a specific email address is registered in a NocoDB instance by observing response differences from the password reset endpoint. While this does not expose credentials or data directly, it enables targeted account harvesting and social engineering attacks.

Technical details

The vulnerability is an information disclosure flaw (CWE-204: Observable Response Discrepancy) in the POST /api/v2/auth/password/forgot endpoint. The endpoint returned different HTTP responses for registered emails (success message) versus unregistered emails ('Your email has not been registered.'), allowing unauthenticated attackers to enumerate valid email accounts without authentication or preconditions. No user interaction is required. The attack requires only network access to the endpoint and the ability to send HTTP requests. The fix was implemented in version 0.301.3 to return uniform responses for all emails. No evidence of exploitation in the wild has been reported.

Affected products

  • NocoDB nocodb <= 0.301.2

Timeline

  • 2026-03-02: disclosed
  • 2026-02-27: patched: version 0.301.3 released

References

Related threats