CVE-2026-53926
Last modified
CVE-2026-53926 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, revokeAllOAuthTokensByUser in the users service is an empty stub being called from passwordChange, passwordForgot, and passwordReset. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, revokeAllOAuthTokensByUser in the users service is an empty stub being called from passwordChange, passwordForgot, and passwordReset. OAuth access and refresh tokens were not revoked when the user changed, reset, or recovered their password, leaving an attacker-issued OAuth grant valid after the user believed they had locked the attacker out. This vulnerability is fixed in 2026.05.1.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-53926?
How severe is CVE-2026-53926?
How do I fix CVE-2026-53926?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53915In JetBrains GoLand before 2026.1.3 remote code execution wa…8.8
- CVE-2026-53916Memory Allocation with Excessive Size Value vulnerability in…7.5
- CVE-2026-53917Memory Allocation with Excessive Size Value vulnerability in…7.5
- CVE-2026-5392Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 me…5.4
- CVE-2026-53923vLLM is an inference and serving engine for large language m…7.5
- CVE-2026-53925Glances is an open-source system cross-platform monitoring t…7.8
- CVE-2026-53927NocoDB is software for building databases as spreadsheets. P…5.1
- CVE-2026-53928NocoDB is software for building databases as spreadsheets. P…6.3
- CVE-2026-53929NocoDB is software for building databases as spreadsheets. P…5.1
- CVE-2026-5393Dual-Algorithm CertificateVerify out-of-bounds read. When pr…9.1
- CVE-2026-53930NocoDB is software for building databases as spreadsheets. P…5.1
- CVE-2026-53931NocoDB is software for building databases as spreadsheets. P…6.9
Are you affected by CVE-2026-53926?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
