CVE Explorer
CVE-2026-47279
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without verifying that the column was visible in the shared view, so anyone holding a share UUID could read links from any LTAR column on the view's table — including columns the view owner had hidden. publicMmList, publicHmList, and relDataList already ensured that the requested column belonged to the view's model, but did not check the vi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"nocodb","vendor":"nocodb","versions":[{"status":"affected","version":"< 2026.05.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b23a80b11ad8af0a1c1aa44ad45d8c2c0771f43d103cc182a0ed82b021160b6a · sha256:74a765e5a0684ca5… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b23a80b11ad8af0a1c1aa44ad45d8c2c0771f43d103cc182a0ed82b021160b6a · sha256:74a765e5a0684ca5… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b23a80b11ad8af0a1c1aa44ad45d8c2c0771f43d103cc182a0ed82b021160b6a · sha256:74a765e5a0684ca5… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/nocodb/nocodb/security/advisories/GHSA-9wgh-m22w-9xj8","tags":["x_refsource_CONFIRM"],"url":"https://github.com/nocodb/nocodb/security/advisories/GHSA-9wgh-m22w-9xj8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b23a80b11ad8af0a1c1aa44ad45d8c2c0771f43d103cc182a0ed82b021160b6a · sha256:74a765e5a0684ca5… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.