CVE-2026-28361: NocoDB Missing Ownership Validation in MCP Token Operations
The MCP token service did not validate token ownership, allowing a Creator within the same base to read, regenerate, or delete another user’s MCP tokens if the token ID was known.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-28361 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →