Impact
Adalo’s no‑code app builder (versions 1 and 2) allows an attacker to enumerate database identifiers (dbId) and retrieve full user records. The platform does not enforce authentication or authorization on the dbId parameter, nor does it implement data minimization or privacy‑by‑design safeguards, so personal identifiers and other sensitive data can be exposed to unauthorized actors.
Affected Systems
The vulnerability exists in Adalo No‑Code App Builder releases 1 and 2. Attackers can trigger the flaw by passing any dbId value to the API; no other vendors or products are affected according to the advisory.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, indicating a medium‑to‑high severity data‑exposure risk. The EPSS score of less than 1 % and its absence from the CISA KEV catalog suggest that exploitation is currently rare, but the lack of authentication checks on the dbId parameter makes the vulnerability readily exploitable once an attacker can enumerate valid identifiers. The likely attack vector is through the public API where dbId is accepted without proper authorization controls.
OpenCVE Enrichment