Junglewise Threat Intelligence

CVE-2026-28396: NocoDB refresh token not revoked on password reset

CVE-2026-28396 · Severity: medium · CVSS 4 · Published 2026-03-02

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB is a popular open-source database management and collaboration platform. When a user resets their password, the application fails to revoke previously issued refresh tokens, allowing an attacker who previously stole a refresh token to continue accessing the account and generating valid authentication tokens until that stolen token naturally expires.

Technical details

The vulnerability is a session expiration weakness (CWE-613) in NocoDB's password reset flow. The passwordReset() function in users.service.ts increments the token_version field (which invalidates JWTs), but fails to call UserRefreshToken.deleteAllUserToken() to revoke refresh tokens. The refreshToken() method only validates token existence, not token_version compatibility. In contrast, passwordChange() and signOut() correctly delete all refresh tokens. An attacker with a previously stolen refresh token can exploit this to mint new valid JWTs after the victim resets their password, maintaining unauthorized access until the stolen refresh token's natural expiration. The patch is available in version 0.301.3.

Affected products

  • NocoDB NocoDB <= 0.301.2

Timeline

  • 2026-03-02: disclosed: Advisory published
  • 2026-03-02: patched: Fix released in version 0.301.3

References

Related threats