Vulnerability Description
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-level-creator permissions can exploit prototype pollution in the `/api/v2/meta/connection/test` endpoint, causing all database write operations to fail application-wide until server restart. While the pollution technically bypasses SUPER_ADMIN authorization checks, no practical privileged actions can be performed because database operations fail immediately after pollution. Version 0.301.0 patches the issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nocodb | Nocodb | < 0.301.0 |
Related Weaknesses (CWE)
References
- https://github.com/nocodb/nocodb/security/advisories/GHSA-95ff-46g6-6gw9Vendor AdvisoryExploit
FAQ
What is CVE-2026-24766?
CVE-2026-24766 is a vulnerability with a CVSS score of 4.9 (MEDIUM). NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-level-creator permissions can exploit prototype pollution in the `/api/v2/meta/conne...
How severe is CVE-2026-24766?
CVE-2026-24766 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-24766?
Check the references section above for vendor advisories and patch information. Affected products include: Nocodb Nocodb.