CVE-2026-46554

Source
https://cve.org/CVERecord?id=CVE-2026-46554
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46554.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-46554
Aliases
Published
2026-06-23T20:30:46.361Z
Modified
2026-07-15T01:48:58.705264783Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
NocoDB: Stale Auth Cache After API Token Deletion
Details

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authenticate requests until their cache entry expired, because the auth cache was not invalidated by token value at deletion time. The API token deletion path removed the database row but did not evict the token-value keyed entry from the auth cache. The auth middleware therefore continued to accept the deleted token until the cache entry aged out, leaving a deletion-to-revocation window of up to three days. This vulnerability is fixed in 2026.04.4.

Database specific
{
    "cwe_ids": [
        "CWE-613"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46554.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nocodb/nocodb

Affected ranges

Type
GIT
Repo
https://github.com/nocodb/nocodb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2026.04.4"
        }
    ]
}

Affected versions

0.*
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.100.0
0.100.1
0.100.2
0.101.0
0.101.0-beta.0
0.101.2
0.104.1
0.104.2
0.104.3
0.105.0
0.105.1
0.105.2
0.105.3
0.106.0
0.106.0-beta.0
0.106.0-beta.1
0.106.1
0.107.0
0.107.0-beta.0
0.107.0-beta.1
0.107.1
0.107.2
0.107.3
0.107.4
0.107.5
0.108.0
0.108.0-beta.0
0.108.1
0.109.0
0.109.1
0.109.2
0.109.3
0.109.4
0.109.5
0.109.6
0.109.7
0.11.0
0.11.1
0.11.10
0.11.11
0.11.12
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.20
0.11.21
0.11.22
0.11.23
0.11.24
0.11.25
0.11.26
0.11.28
0.11.29
0.11.3
0.11.30
0.11.31
0.11.33
0.11.34
0.11.36
0.11.39
0.11.4
0.11.40
0.11.41
0.11.42
0.11.43
0.11.44
0.11.45
0.11.46
0.11.5
0.11.6
0.11.7
0.11.9
0.111.0
0.111.1
0.111.2
0.111.3
0.111.4
0.200.0
0.202.0
0.202.10
0.202.5
0.202.6
0.202.7
0.202.8
0.202.9
0.203.0
0.203.1
0.203.2
0.301.3-test-build-3
0.301.3-test-build-4
0.301.3-test-build-5
0.301.3-test-build-6
0.301.3-test-build-7
0.301.4
0.301.5
0.301.5-test.1
0.4.5
0.4.8
0.4.9
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.83.1
0.83.2
0.83.3
0.83.4
0.83.5
0.83.6
0.83.8
0.84.1
0.84.10
0.84.12
0.84.13
0.84.14
0.84.15
0.84.16
0.84.2
0.84.3
0.84.6
0.84.7
0.84.8
0.84.9
0.9
0.90.0
0.90.1
0.90.10
0.90.11
0.90.3
0.90.4
0.90.7
0.90.8
0.90.9
0.91.0
0.91.1
0.91.10
0.91.6
0.91.7
0.91.8
0.91.9
0.92.0
0.92.1
0.92.2
0.92.3
0.92.4
0.96.0
0.96.4
0.97.0
0.98.1
0.98.2
0.98.3
0.98.4
0.99.0
0.99.1
0.99.2
2026.*
2026.04.0
2026.04.1
2026.04.2
2026.04.3
v0.*
v0.10.0
v0.4.2
v0.4.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46554.json"