CVE-2026-53928Disclosure

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a stolen refresh token survived a password-forgot flow and could be used to mint fresh JWTs even after the user reset their password. passwordChange and passwordReset deleted the user's refresh tokens, but passwordForgot only rotated token_version and revoked OAuth tokens — it did not call UserRefreshToken.deleteAllUserToken(user.id). An attacker holding a captured refresh cookie could still exchange it for a new access token after the victim triggered the recovery flow. This vulnerability is fixed in 2026.05.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-06-23); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-23: 2Mentions · 2026-06-24: 1Mentions · 2026-08-27: 1Technical Details · 2026-06-23: 2Technical Details · 2026-06-24: 106-2306-2408-27
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-232
Disclosure2
2026-06-241
Disclosure1
2026-08-271
General1
Full discourse4 posts
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    108 CVE-2025-58434 CVE-2025-59057 CVE-2025-59343 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-62228 CVE-2025-62232 CVE-2025-64756 CVE-2026-21884 CVE-2026-22706 CVE-2026-22807 CVE-2026-23630 CVE-2026-24015 CVE-2026-24899 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-33264 CVE-2026-33413 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40006 CVE-2026-40007 CVE-2026-40009 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40452 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42275 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-44247 CVE-2026-44309 CVE-2026-44310 CVE-2026-44442 CVE-2026-44446 CVE-2026-44705 CVE-2026-44947 CVE-2026-45022 CVE-2026-45090 CVE-2026-45720 CVE-2026-45723 CVE-2026-45726 CVE-2026-46553 CVE-2026-46554 CVE-2026-47733 CVE-2026-4800 CVE-2026-48978 CVE-2026-49478 CVE-2026-50285 CVE-2026-52808 CVE-2026-52809 CVE-2026-53926 CVE-2026-53928 CVE-2026-53929 CVE-2026-53930 CVE-2026-56842 CVE-2026-60076 CVE-2026-60077 CVE-2026-75605 CVE-2026-9103

    Post summary

    The text contains only a list of CVE identifiers with no additional context or technical information.

    30124138.2K
    3.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-53928 Stolen Refresh Token Persistence in NocoDB Password Recovery Flow Prior to 2026.05.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-53928

    Post summary

    The text announces CVE‑2026‑53928, detailing a vulnerability in NocoDB's password recovery flow that allows stolen refresh tokens to persist, with no PoC, exploit, patch, or active exploitation mentioned.

    00000103
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-53928 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a stolen refresh token survived a password-forgot flow and could be used to mint fresh … https://www.cve.org/CVERecord?id=CVE-2026-53928 ----- Traducción: CVE-2026-53928 Noc… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑53928 in NocoDB, noting that stolen refresh tokens can survive a password‑reset flow and be reused, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000037
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-53928 NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a stolen refresh token survived a password-forgot flow and could be used to mint fresh … https://www.cve.org/CVERecord?id=CVE-2026-53928

    Post summary

    The CVE describes a flaw in NocoDB’s password‑reset flow that allows a stolen refresh token to generate new tokens, with no evidence of PoC, exploitation, or patching in the provided text.

    00000647
    57.7K followersView on X

Explore more