Junglewise Threat Intelligence

CVE-2026-47381: NocoDB authorization bypass in testConnection endpoint

CVE-2026-47381 · Severity: medium · CVSS 4 · Published 2026-06-23

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB is an open-source platform that turns databases into smart spreadsheets for business collaboration. A security flaw allowed users in one workspace to access and test database connections belonging to other organizations or teams by simply providing the connection ID. This could allow an unauthorized user to verify and potentially interact with external database integrations they do not own, compromising the isolation between different customers or departments.

Technical details

An authorization bypass vulnerability exists in NocoDB's 'testConnection' endpoint. The root cause is that the endpoint fetched integration details using 'RootScopes.BYPASS' and performed a permission check that only verified if the caller held an owner or creator role on any base in any workspace, rather than the specific workspace owning the integration. An attacker with creator/owner permissions in their own workspace could trigger connection tests for integrations in other workspaces by supplying the target integration ID. This allows cross-tenant access to integration configurations and the ability to exercise database credentials belonging to other workspaces. The issue is resolved in version 2026.05.1 by scoping permission lookups to the integration's specific workspace ID.

Affected products

  • nocodb NocoDB < 2026.05.1

Timeline

  • 2026-06-04: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: CVE published to NVD
  • 2026-05-01: patched: Fixed in version 2026.05.1

References

Related threats