Description
This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a minimal leaderboard component may return user records containing emails, UUIDs, and custom fields. The combination of wildcard CORS behavior, long‑lived twenty‑day JWTs, and the absence of token revocation allows attackers to gather sensitive personal information from any Adalo application.
Published: 2026-07-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adalo No‑Code App Builder exposes user data through its minimal leaderboard component, which returns email addresses, UUIDs, and custom fields without requiring any application‑specific secrets. The underlying weakness stems from wildcard CORS configuration, long‑lived twenty‑day JWTs, and an absence of token revocation, resulting in an authorization bypass that allows attackers to harvest personal information. This vulnerability is classified under improper authorization and insufficient credential protection.

Affected Systems

All installations of Adalo No‑Code App Builder that deploy the default leaderboard component are affected. The CNA data does not specify version limits, so every current and legacy deployment that includes the component is potentially exposed.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% points to a low but non‑zero probability of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw remotely by sending a single request to the leaderboard endpoint, gaining access to sensitive personal data throughout the twenty‑day window in which the JWT remains valid. Because the tokens cannot be revoked, the attack surface persists for the entire token lifetime, enabling repeated harvesting by the same actor.

Generated by OpenCVE AI on August 3, 2026 at 04:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adalo App Builder to the latest release that shortens JWT validity periods and implements token revocation
  • Configure the leaderboard endpoint’s CORS settings to allow requests only from authenticated users
  • Disable or remove the leaderboard component when it is not needed, or restrict its visibility to a trusted user group

Generated by OpenCVE AI on August 3, 2026 at 04:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 03 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285
CWE-613

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285
CWE-613

Sat, 25 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285
CWE-613

Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285
CWE-613

Tue, 21 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285
CWE-613

Thu, 16 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285
CWE-613

Mon, 13 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285
CWE-613

Sun, 12 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sat, 11 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Fri, 10 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-522

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Adalo No-code App Builder
Adalo No-code App Builder app Builder
Vendors & Products Adalo No-code App Builder
Adalo No-code App Builder app Builder

Fri, 10 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-522

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a minimal leaderboard component may return user records containing emails, UUIDs, and custom fields. The combination of wildcard CORS behavior, long‑lived twenty‑day JWTs, and the absence of token revocation allows attackers to gather sensitive personal information from any Adalo application.
Title Insufficiently Protected Credentials
References

Subscriptions

Adalo No-code App Builder App Builder
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-07-09T15:13:00.989Z

Reserved: 2026-06-02T17:59:57.666Z

Link: CVE-2026-10708

cve-icon Vulnrichment

Updated: 2026-07-09T15:12:50.597Z

cve-icon NVD

Status : Deferred

Published: 2026-07-08T15:16:25.377

Modified: 2026-07-09T19:49:55.763

Link: CVE-2026-10708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T05:00:15Z

Weaknesses