CVE-2026-18816 Details
Description
A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to improper authentication. The attack may be launched remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. Upgrading to version 2.3.3 addresses this issue. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A vulnerability exists in Baserow versions through 2.3.2, specifically in the 2FA verify endpoint. The issue arises because the endpoint relies on an email field to identify users, even though the 2FA token already contains user identity information from the initial login. This redundancy complicates the authentication process. The vulnerability allows for improper authentication and can be exploited remotely, although the exploitation is considered complex and difficult.
Users can upgrade to Baserow version 2.3.3 to address this vulnerability. Instructions for upgrading can be found in the Baserow repository on GitHub.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 4, 2026CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/baserow/baserow/ | [email protected] | Vendor |
| https://github.com/baserow/baserow/issues/5743 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/baserow/baserow/releases/tag/2.3.3 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-18816 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/857941 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/385815 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/385815/cti | [email protected] | AdvisoryContent Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Baserow | <= 2.3.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | New CVE Received | [email protected] |
Volerion