NocoDB Vulnerable to User Enumeration via Password Reset Endpoint
Description
Published by the National Vulnerability Database
Mar 2, 2026
Published to the GitHub Advisory Database
Mar 2, 2026
Reviewed
Mar 2, 2026
Last updated
Mar 2, 2026
Summary
The password forgot endpoint returned different responses for registered and unregistered emails, allowing user enumeration.
Details
POST /api/v2/auth/password/forgotreturned a success message for registered emails but'Your email has not been registered.'for unknown emails. The fix returns a uniform response regardless of whether the email exists.Impact
An unauthenticated attacker can determine whether an email is registered. No credentials or data are exposed.
Credit
This issue was reported by @Tulgaaaaaaaa.
References