CVE-2026-53926
概要

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, revokeAllOAuthTokensByUser in the users service is an empty stub being called from passwordChange, passwordForgot, and passwordReset. OAuth access and refresh tokens were not revoked when the user changed, reset, or recovered their password, leaving an attacker-issued OAuth grant valid after the user believed they had locked the attacker out. This vulnerability is fixed in 2026.05.1.

公表日 2026年6月24日6:17
登録日 2026年6月27日4:16
最終更新日 2026年6月25日23:21
関連情報、対策とツール
共通脆弱性一覧