Observable Response Discrepancy in NocoDB - CVE-2026-28358
Published: April 27, 2026
NocoDB
Detailed vulnerability description
The vulnerability allows a remote attacker to enumerate registered email addresses.
The vulnerability exists due to observable response discrepancy in the password reset endpoint when handling password reset requests. A remote attacker can send a password reset request with a chosen email address to enumerate registered email addresses.
No credentials or other data are exposed.