NocoDB: Shared-base link access can invite arbitrary users as persistent base members
Published Jun 23, 2026
5.8
MEDIUMCVSS 3.1
EPSS 0.31%
Description
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, shared-base sessions were granted the same base-member capabilities as authenticated viewers. Using only the shared-base UUID (xc-shared-base-id), an attacker could enumerate base members and invite an arbitrary email into the base as a real member. The invited user could then redeem the invite via the normal signup flow and retain authenticated access even after the owner revoked the shared link. Shared-base sessions were mapped to ProjectRoles.VIEWER in packages/nocodb/src/strategies/base-view.strategy/base-view.strategy.ts, and packages/nocodb/src/utils/acl.ts granted baseUserList and userInvite to that role. The shared frontend (packages/nc-gui/composables/useApi/interceptors.ts) deliberately removed auth headers in favour of the shared-base header, but the ACL middleware did not distinguish shared sessions from genuine viewers. This vulnerability is fixed in 2026.04.1.
Affected products
-
Affected
- < 2026.04.1
No data.
No data.
No Red Hat product state for this CVE.
nocodb
npm
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | nocodb | 0 | not fixed |
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38584 Advisory
- https://github.com/advisories/GHSA-chqv-vrj7-qffp Advisory
- https://github.com/nocodb/nocodb/security/advisories/GHSA-chqv-vrj7-qffp x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-46552
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38584 | Advisory | |
| https://github.com/advisories/GHSA-chqv-vrj7-qffp | Advisory | |
| https://github.com/nocodb/nocodb/security/advisories/GHSA-chqv-vrj7-qffp | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-46552 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub