CVE-2026-28360
Severity CVSS v4.0:
LOW
Type:
CWE-256
Plaintext Storage of a Password
Publication date:
02/03/2026
Last modified:
02/03/2026
Description
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored in plaintext in the database and compared using direct string equality. This issue has been patched in version 0.301.3.



