CVE-2026-47279Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without verifying that the column was visible in the shared view, so anyone holding a share UUID could read links from any LTAR column on the view's table — including columns the view owner had hidden. publicMmList, publicHmList, and relDataList already ensured that the requested column belonged to the view's model, but did not check the view-column entry's show flag. This vulnerability is fixed in 2026.05.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-23: 2Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-23: 206-23
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-47279 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without … https://www.cve.org/CVERecord?id=CVE-2026-47279 ----- Traducción: CVE-2026-47279 Noc… http://infoflow.cloud`

    Post summary

    The post discloses CVE‑2026‑47279, outlining that NocoDB’s shared‑view relation endpoints previously accepted unsanitized column IDs before version 2026.05.1, but no PoC, exploit code, patch, or active exploitation details are provided.

    0000029
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-47279 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without … https://www.cve.org/CVERecord?id=CVE-2026-47279

    Post summary

    The announcement describes an NocoDB vulnerability where public endpoints could accept unsanitized column IDs, and notes that the issue was addressed in version 2026.05.1.

    00000721
    57.7K followersView on X

Explore more