CVE-2026-46549

Source
https://cve.org/CVERecord?id=CVE-2026-46549
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46549.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-46549
Aliases
Published
2026-06-23T20:40:24.037Z
Modified
2026-07-15T01:49:18.622991943Z
Severity
  • 2.0 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
Details

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauthscope and oauthgrantedresources to the request user, but the ACL middleware never consulted either. An OAuth token issued with a restricted scope (e.g. MCP-only) therefore inherited the full permissions of the underlying user across all routes; the grantedresources.baseid restriction was bypassed on org-level endpoints that don't populate req.context.baseid. This vulnerability is fixed in 2026.04.1.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46549.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nocodb/nocodb

Affected ranges

Type
GIT
Repo
https://github.com/nocodb/nocodb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2026.04.1"
        }
    ]
}

Affected versions

0.*
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.100.0
0.100.1
0.100.2
0.101.0
0.101.0-beta.0
0.101.2
0.104.1
0.104.2
0.104.3
0.105.0
0.105.1
0.105.2
0.105.3
0.106.0
0.106.0-beta.0
0.106.0-beta.1
0.106.1
0.107.0
0.107.0-beta.0
0.107.0-beta.1
0.107.1
0.107.2
0.107.3
0.107.4
0.107.5
0.108.0
0.108.0-beta.0
0.108.1
0.109.0
0.109.1
0.109.2
0.109.3
0.109.4
0.109.5
0.109.6
0.109.7
0.11.0
0.11.1
0.11.10
0.11.11
0.11.12
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.20
0.11.21
0.11.22
0.11.23
0.11.24
0.11.25
0.11.26
0.11.28
0.11.29
0.11.3
0.11.30
0.11.31
0.11.33
0.11.34
0.11.36
0.11.39
0.11.4
0.11.40
0.11.41
0.11.42
0.11.43
0.11.44
0.11.45
0.11.46
0.11.5
0.11.6
0.11.7
0.11.9
0.111.0
0.111.1
0.111.2
0.111.3
0.111.4
0.200.0
0.202.0
0.202.10
0.202.5
0.202.6
0.202.7
0.202.8
0.202.9
0.203.0
0.203.1
0.203.2
0.301.3-test-build-3
0.301.3-test-build-4
0.301.3-test-build-5
0.301.3-test-build-6
0.301.3-test-build-7
0.301.4
0.301.5
0.301.5-test.1
0.4.5
0.4.8
0.4.9
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.83.1
0.83.2
0.83.3
0.83.4
0.83.5
0.83.6
0.83.8
0.84.1
0.84.10
0.84.12
0.84.13
0.84.14
0.84.15
0.84.16
0.84.2
0.84.3
0.84.6
0.84.7
0.84.8
0.84.9
0.9
0.90.0
0.90.1
0.90.10
0.90.11
0.90.3
0.90.4
0.90.7
0.90.8
0.90.9
0.91.0
0.91.1
0.91.10
0.91.6
0.91.7
0.91.8
0.91.9
0.92.0
0.92.1
0.92.2
0.92.3
0.92.4
0.96.0
0.96.4
0.97.0
0.98.1
0.98.2
0.98.3
0.98.4
0.99.0
0.99.1
0.99.2
2026.*
2026.04.0
v0.*
v0.10.0
v0.4.2
v0.4.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46549.json"