CVE-2026-10706 Details
Description
In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavior across multiple applications via dbId enumeration. The platform does not implement data minimization, privacy by design, or implement appropriate technical safeguards, allowing sensitive information to be exposed to unauthorized parties.
A vulnerability in Adalo's no-code app builder, affecting versions 1 and 2, allows authenticated users to extract full user records from the database API of any application on the platform. This issue arises from a lack of proper authorization checks, enabling the retrieval of complete user data, including unrequested fields, across more than one million applications. The vulnerability is exacerbated by a permissive CORS policy and the plaintext storage of text files, with evidence suggesting that deleted records may still be accessible.
Adalo has acknowledged this vulnerability but has not yet released a patch. Users are advised to avoid storing sensitive information in Adalo collections until a fix is available and to monitor their accounts for suspicious activity.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 8, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.cert.org/vuls/id/849433 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Adalo | <= 2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |
Volerion