Junglewise Threat Intelligence

CVE-2026-53926: NocoDB insufficient session expiration in OAuth token revocation

CVE-2026-53926 · Severity: medium · CVSS 4 · Published 2026-06-23

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB, a platform for building databases as spreadsheets, failed to properly cancel active login sessions when a user changed or reset their password. This means that if an attacker had already gained access to an account via an OAuth token, they would remain logged in even after the legitimate user updated their security credentials. This could lead to unauthorized data access and persistent account compromise despite the user's attempts to secure their account.

Technical details

A vulnerability exists in NocoDB where the 'revokeAllOAuthTokensByUser' function in the users service was implemented as an empty stub. Consequently, when security events such as passwordChange, passwordForgot, or passwordReset were triggered, existing OAuth access and refresh tokens remained valid. An attacker with a previously issued OAuth grant could maintain persistent access to the user's account even after a password reset. The fix, introduced in version 2026.05.1, implements proper delegation to 'OAuthToken.revokeAllByUser' to delete relevant database rows and invalidate authentication caches.

Affected products

  • nocodb nocodb < 2026.05.1

Timeline

  • 2026-06-04: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: CVE published to NVD

References

Related threats