Junglewise Threat Intelligence

CVE-2026-28360: NocoDB plaintext storage of shared view passwords

CVE-2026-28360 · Severity: medium · CVSS 4 · Published 2026-03-02

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB is a popular open-source database management platform that allows users to share database views with passwords for access control. This vulnerability stores those view passwords in plaintext in the database instead of hashing them; if an attacker gains database access through a separate breach or misconfiguration, the shared view passwords become immediately visible and can be reused to access sensitive data views.

Technical details

The vulnerability is a plaintext password storage issue (CWE-256) in the nc_views database table where shared view passwords are stored unhashed. Verification of passwords uses direct string equality comparison (=== operator) across public-datas.service.ts, public-metas.service.ts, and calendar-datas.service.ts rather than cryptographic comparison. The attack requires prior compromise of the NocoDB database itself or its underlying storage. Once database access is obtained, shared view passwords are immediately readable without additional effort. The vulnerability is fixed in version 0.301.3; all versions up to 0.301.2 are affected.

Affected products

  • NocoDB NocoDB 0 to 0.301.2

Timeline

  • 2026-03-02: disclosed: Advisory published
  • 2026-03-02: patched: Fixed in version 0.301.3

References

Related threats