PT-2026-56454 · Adalo · Adalo

·

CVE-2026-10706

·

Published

2026-07-08

·

Updated

2026-07-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adalo versions 1 through 2
Description Attackers can extract complete user records and correlate user behavior across multiple applications through the enumeration of the dbId variable. This occurs because the platform lacks data minimization, privacy by design, and necessary technical safeguards, which leads to the exposure of sensitive information to unauthorized parties.
Recommendations Update Adalo versions 1 through 2 to a version that implements appropriate technical safeguards and data minimization to prevent dbId enumeration.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-10706

Affected Products

Adalo