Description
A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to improper authentication. The attack may be launched remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. Upgrading to version 2.3.3 addresses this issue. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-08-04
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Baserow up to version 2.3.2 where the verify function in the two‑factor authentication endpoint allows an attacker to bypass authentication controls. This flaw results in improper authentication, letting an adversary potentially assume the identity of a legitimate user. The weakness is a classic authentication failure (CWE‑287) and can be used to gain unauthorized access to the application’s data and administrative functions.

Affected Systems

The affected product is Baserow from the vendor Baserow. All deployments running any release prior to 2.3.3 are vulnerable, with the last known safe release being 2.3.3 and later versions mitigating the issue.

Risk and Exploitability

The CVSS score of 2.3 indicates a low severity assessment, and no EPSS score is available, so the likelihood of exploitation is unclear. The vulnerability can be exploited remotely, but the description notes that it requires high complexity and is difficult to execute. It is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. Nevertheless, the impact of unauthorized authentication can be substantial if an attacker gains access to privileged accounts.

Generated by OpenCVE AI on August 4, 2026 at 23:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch by upgrading to Baserow 2.3.3 or newer
  • Implement monitoring on authentication logs to detect abnormal login attempts and investigate suspicious activity
  • Consider disabling two‑factor authentication for users that do not require it and enforce strong password policies

Generated by OpenCVE AI on August 4, 2026 at 23:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to improper authentication. The attack may be launched remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. Upgrading to version 2.3.3 addresses this issue. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title Baserow 2FA Verify Endpoint views.py verify improper authentication
First Time appeared Baserow
Baserow baserow
Weaknesses CWE-287
CPEs cpe:2.3:a:baserow:baserow:*:*:*:*:*:*:*:*
Vendors & Products Baserow
Baserow baserow
References
Metrics cvssV2_0

{'score': 4.6, 'vector': 'AV:N/AC:H/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-04T21:45:08.665Z

Reserved: 2026-08-04T12:54:06.562Z

Link: CVE-2026-18816

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:00:03Z

Weaknesses