AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-10706

HIGH · CVSS 7.5 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

Adalo's no-code app builder (Versions 1 and 2) is vulnerable to dbId enumeration, enabling attackers to extract complete user records and track user behavior across various applications. This lack of data minimization and inadequate technical safeguards can lead to significant exposure of sensitive information. Organizations using this platform should prioritize addressing this vulnerability to protect user data and maintain compliance with privacy regulations.

CVE
CVE-2026-10706
Severity
HIGH
CVSS
7.5
EPSS
0.38%

Original NVD Description

In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavior across multiple applications via dbId enumeration. The platform does not implement data minimization, privacy by design, or implement appropriate technical safeguards, allowing sensitive information to be exposed to unauthorized parties.