CVE-2026-28360

Severity CVSS v4.0:
LOW
Type:
CWE-256 Plaintext Storage of a Password
Publication date:
02/03/2026
Last modified:
02/03/2026

Description

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored in plaintext in the database and compared using direct string equality. This issue has been patched in version 0.301.3.